CVE-2026-35030 (CVSS 9.4): LiteLLM JWT Auth Bypass, Config RCE, and How to Rotate After the Supply Chain Attack
Introduction
Two critical CVEs in LiteLLM landed this week. CVE-2026-35030 is CVSS 9.4. CVE-2026-35029, CVSS 8.7, chains into remote code execution on the proxy. Both are patched in 1.83.0. Running al
armor1.hashnode.dev4 min read