From 2c5048b7b6b59de6734374eedd88ff795f4f05b3 Mon Sep 17 00:00:00 2001 From: Alexsander Hamir Date: Wed, 14 Jan 2026 12:35:31 -0800 Subject: [PATCH] security: avoid logging sensitive data in usage dict - Replace full usage dict logging with keys and type only - Prevents potential exposure of sensitive information in debug logs - Maintains debugging capability without security risk --- litellm/litellm_core_utils/litellm_logging.py | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/litellm/litellm_core_utils/litellm_logging.py b/litellm/litellm_core_utils/litellm_logging.py index b16cdc51449..88bf010aca7 100644 --- a/litellm/litellm_core_utils/litellm_logging.py +++ b/litellm/litellm_core_utils/litellm_logging.py @@ -4972,7 +4972,17 @@ def _try_create_usage_from_dict(usage: dict) -> Optional[Usage]: try: return Usage(**usage) except (TypeError, ValueError) as e: - verbose_logger.debug(f"Error creating Usage from dict: {e}, usage: {usage}") + # Avoid logging full dict contents, which may include sensitive data + try: + usage_keys = list(usage.keys()) + except Exception: + usage_keys = None + verbose_logger.debug( + "Error creating Usage from dict: %s, usage keys: %s, usage type: %s", + e, + usage_keys, + type(usage), + ) return None