v1.86.2 - Path-Handling Hardening Backport
Deploy this version​
- Docker
- Pip
docker run \
-e STORE_MODEL_IN_DB=True \
-p 4000:4000 \
docker.litellm.ai/berriai/litellm:1.86.2
pip install litellm==1.86.2
v1.86.2 is a patch release on top of v1.86.1. It backports the path-handling hardening covered in the host-header authentication bypass advisory.
Bug Fixes​
- Proxy auth / routing
- Route the proxy's path-dependent call sites through
get_request_route()so they all derive the request route from the ASGI scope rather than theHost-reconstructed URL - PR #28547
- Route the proxy's path-dependent call sites through
Full Changelog​
https://github.com/BerriAI/litellm/compare/v1.86.1...v1.86.2