mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-10 03:28:53 +00:00
Add security vulnerability scan report to v1.81.14 release notes
This commit is contained in:
parent
1576033495
commit
dee2a62686
1 changed files with 65 additions and 0 deletions
|
|
@ -489,6 +489,71 @@ graph LR
|
|||
|
||||
---
|
||||
|
||||
## Security
|
||||
|
||||
We run [Grype](https://github.com/anchore/grype) and [Trivy](https://github.com/aquasecurity/trivy) security scans on every LiteLLM Docker image. Here's the vulnerability report for this release across all published images:
|
||||
|
||||
### Docker Image Scan Summary
|
||||
|
||||
| Image | Critical | High | Medium | Low |
|
||||
|-------|----------|------|--------|-----|
|
||||
| `ghcr.io/berriai/litellm:main-latest` | **0** ✅ | 4 unique CVEs | 4 | 1 |
|
||||
| `ghcr.io/berriai/litellm-ee:main-latest` | **0** ✅ | 4 unique CVEs | 4 | 1 |
|
||||
| `ghcr.io/berriai/litellm-non_root:main-latest` | **1** | 11 unique CVEs | 6 | 2 |
|
||||
| `ghcr.io/berriai/litellm-database:main-latest` | **1** | 7 unique CVEs | 5 | 1 |
|
||||
| `ghcr.io/berriai/litellm-spend_logs:main-latest` | **4** | 35 matches | 40 | 10 |
|
||||
|
||||
:::note
|
||||
Vulnerability counts are based on full image scans including build-time tooling. High match counts are often inflated by packages like `minimatch` appearing at multiple versions; the unique CVE counts above reflect the actual distinct vulnerabilities.
|
||||
:::
|
||||
|
||||
### Critical Severity
|
||||
|
||||
**1. Node.js Critical (non-root, database, spend_logs images):**
|
||||
Node.js 24.12.0 is used **only** for the Admin UI build and Prisma client generation — it is **not** part of the LiteLLM Python application runtime.
|
||||
|
||||
| Package | Vulnerability | Description | Fix Version |
|
||||
|---------|---------------|-------------|-------------|
|
||||
| `node` | CVE-2025-55130 | Node.js critical vulnerability | 20.20.0 |
|
||||
|
||||
**2. OpenSSL & Go Critical (spend_logs image only):**
|
||||
The `spend_logs` image contains additional vulnerabilities in the underlying Go modules and system libraries.
|
||||
|
||||
| Package | Vulnerability | Description | Fix Version |
|
||||
|---------|---------------|-------------|-------------|
|
||||
| `libcrypto3`, `libssl3` | CVE-2025-15467 | OpenSSL critical vulnerability | 3.3.6-r0 |
|
||||
| `stdlib` (Go) | CVE-2025-68121 | Go standard library critical vulnerability | 1.24.13+ |
|
||||
|
||||
### High Severity
|
||||
|
||||
All high-severity vulnerabilities are in **npm/Node.js build-time dependencies** or system-level libraries — they are **not** in the LiteLLM Python application code.
|
||||
|
||||
**Present in all images:**
|
||||
|
||||
| Package | Vulnerability | Description | Fix Version |
|
||||
|---------|---------------|-------------|-------------|
|
||||
| `minimatch` | CVE-2026-26996 | DoS via specially crafted glob patterns | 10.2.1+ / 9.0.6+ |
|
||||
| `minimatch` | CVE-2026-27903 | DoS due to unbounded recursive backtracking | 10.2.3+ / 9.0.7+ |
|
||||
| `minimatch` | CVE-2026-27904 | DoS via catastrophic backtracking in glob expressions | 10.2.3+ / 9.0.7+ |
|
||||
| `tar` | CVE-2026-26960 / GHSA-83g3-92jg-28cx | Arbitrary file read/write via malicious archive hardlinks | 7.5.8 |
|
||||
|
||||
### Medium Severity (all images)
|
||||
|
||||
| Package | Vulnerability | Status |
|
||||
|---------|---------------|--------|
|
||||
| `pypdf` 6.7.2 | GHSA-x7hp-r3qg-r3cj | Fix available in 6.7.3 |
|
||||
| Python 3.13 | CVE-2025-15366, CVE-2025-15367, CVE-2025-12781 | No upstream fix available |
|
||||
|
||||
### Recommendations
|
||||
|
||||
- **LiteLLM Main & EE images** (`litellm:main-latest`, `litellm-ee:main-latest`) have the best security posture with **0 critical vulnerabilities**.
|
||||
- All HIGH/CRITICAL findings in the main images relate to build-time Node.js/npm tooling, not the Python runtime.
|
||||
- We are actively monitoring upstream Python and system library fixes for remaining medium-severity vulnerabilities.
|
||||
|
||||
To report a security vulnerability, email support@berri.ai with details and steps to reproduce.
|
||||
|
||||
---
|
||||
|
||||
## Documentation Updates
|
||||
|
||||
- Add OpenAI Agents SDK with LiteLLM guide - [PR #21311](https://github.com/BerriAI/litellm/pull/21311)
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue