From 9498f330d735cfd7d62857c1bda760089671f1ea Mon Sep 17 00:00:00 2001 From: samearth17 Date: Mon, 10 Aug 2026 00:18:14 +0530 Subject: [PATCH 1/4] fix(router): apply cache_kwargs when Redis is not configured --- litellm/router.py | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/litellm/router.py b/litellm/router.py index feaf69a44ae..e7d91859ec6 100644 --- a/litellm/router.py +++ b/litellm/router.py @@ -528,6 +528,10 @@ class Router: cache_type: Literal["local", "redis", "redis-semantic", "s3", "disk"] = "local" # default to an in-memory cache redis_cache = None cache_config: Final[dict[str, Any]] = {} + # FIX: Apply cache_kwargs regardless of whether Redis is used + cache_config.update(cache_kwargs) + if "type" in cache_kwargs: + cache_type = cache_kwargs["type"] self.client_ttl = client_ttl if redis_url is not None or (redis_host is not None and redis_port is not None): From 9a6366e90cd37fb39b2ffa97c193e15416155360 Mon Sep 17 00:00:00 2001 From: samearth17 Date: Mon, 10 Aug 2026 00:43:16 +0530 Subject: [PATCH 2/4] fix(router): prevent duplicate 'type' argument in cache initialization --- litellm/router.py | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/litellm/router.py b/litellm/router.py index e7d91859ec6..3804a70797d 100644 --- a/litellm/router.py +++ b/litellm/router.py @@ -530,8 +530,10 @@ class Router: cache_config: Final[dict[str, Any]] = {} # FIX: Apply cache_kwargs regardless of whether Redis is used cache_config.update(cache_kwargs) - if "type" in cache_kwargs: - cache_type = cache_kwargs["type"] + if "type" in cache_config: + # Pop removes 'type' from cache_config and assigns it to cache_type. + # This prevents passing 'type' twice to litellm.Cache() later. + cache_type = cache_config.pop("type") self.client_ttl = client_ttl if redis_url is not None or (redis_host is not None and redis_port is not None): From c3ddf8991505f401277e557cd2a07454e38efb77 Mon Sep 17 00:00:00 2001 From: samearth17 Date: Mon, 10 Aug 2026 01:00:11 +0530 Subject: [PATCH 3/4] security(router): prevent global cache hijacking via client-provided cache_kwargs --- litellm/router.py | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/litellm/router.py b/litellm/router.py index 3804a70797d..0ba889636b3 100644 --- a/litellm/router.py +++ b/litellm/router.py @@ -563,8 +563,14 @@ class Router: if cache_responses: if litellm.cache is None: - # the cache can be initialized on the proxy server. We should not overwrite it - litellm.cache = litellm.Cache(type=cache_type, **cache_config) + # SECURITY FIX: Do not allow a Router to initialize the global cache + # with client-provided cache_kwargs. This prevents cache exfiltration. + # The global cache must be initialized by the server admin or proxy config. + verbose_router_logger.warning( + "cache_responses=True but litellm.cache is None. " + "Global cache will not be initialized by the Router for security reasons. " + "Please configure litellm.cache globally." + ) self.cache_responses = cache_responses self.cache = DualCache( redis_cache=redis_cache, in_memory_cache=InMemoryCache() From e19ed193f19974b0e2214284b0b4b030d8e31bc6 Mon Sep 17 00:00:00 2001 From: samearth17 Date: Mon, 10 Aug 2026 01:10:10 +0530 Subject: [PATCH 4/4] security(router): prevent global cache hijacking via client-provided cache_kwargs --- litellm/router.py | 8 ++------ 1 file changed, 2 insertions(+), 6 deletions(-) diff --git a/litellm/router.py b/litellm/router.py index 0ba889636b3..a43f4f79d80 100644 --- a/litellm/router.py +++ b/litellm/router.py @@ -525,19 +525,15 @@ class Router: self.deployment_names: list = [] # names of models under litellm_params. ex. azure/chatgpt-v-2 self.deployment_latency_map = {} ### CACHING ### - cache_type: Literal["local", "redis", "redis-semantic", "s3", "disk"] = "local" # default to an in-memory cache redis_cache = None cache_config: Final[dict[str, Any]] = {} # FIX: Apply cache_kwargs regardless of whether Redis is used cache_config.update(cache_kwargs) if "type" in cache_config: - # Pop removes 'type' from cache_config and assigns it to cache_type. - # This prevents passing 'type' twice to litellm.Cache() later. - cache_type = cache_config.pop("type") - + # Pop removes 'type' from cache_config to prevent it from being pass + cache_config.pop("type") self.client_ttl = client_ttl if redis_url is not None or (redis_host is not None and redis_port is not None): - cache_type = "redis" if redis_url is not None: cache_config["url"] = redis_url