---
title: "v1.86.2 - Path-Handling Hardening Backport"
url: "/release_notes/v1.86.2/v1-86-2"
canonical_url: "https://docs.litellm.ai/release_notes/v1.86.2/v1-86-2"
type: "release-notes"
last_updated: "2026-10-01"
related:
  - "/release_notes/v1.86.3/v1-86-3"
  - "/release_notes/v1.86.1/v1-86-1"
---
# v1.86.2 - Path-Handling Hardening Backport

> Index of all LiteLLM docs: https://docs.litellm.ai/llms.txt

## Deploy this version

**Docker**

```bash
docker run \
-e STORE_MODEL_IN_DB=True \
-p 4000:4000 \
docker.litellm.ai/berriai/litellm:1.86.2
```

**Pip**

```bash
pip install litellm==1.86.2
```

`v1.86.2` is a patch release on top of [`v1.86.1`](/release_notes/v1.86.1/v1-86-1). It backports the path-handling hardening covered in the [host-header authentication bypass advisory](/blog/host-header-auth-bypass).

### Bug Fixes

- **Proxy auth / routing**
    - Route the proxy's path-dependent call sites through `get_request_route()` so they all derive the request route from the ASGI scope rather than the `Host`-reconstructed URL - [PR #28547](https://github.com/BerriAI/litellm/pull/28547)

## Full Changelog

https://github.com/BerriAI/litellm/compare/v1.86.1...v1.86.2

## Related pages

- [v1.86.3](https://docs.litellm.ai/release_notes/v1.86.3/v1-86-3.md)
- [v1.86.1](https://docs.litellm.ai/release_notes/v1.86.1/v1-86-1.md)
