CISA Flags LiteLLM, Kestra, and Starlette CVEs as Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency added seven CVEs to its Known Exploited Vulnerabilities catalog in the second week of September 2026, three of which directly affect common self-hosted AI infrastructure. LiteLLM, a popular AI gateway proxy, carries a flaw exposing an unauthenticated admin endpoint that leaks all configured API keys in a single request. Kestra, widely used for AI pipeline orchestration, has a remote code execution vulnerability allowing attackers to run arbitrary commands via crafted workflow definitions. Starlette, the underlying framework for roughly 70% of self-hosted AI model servers built on FastAPI, contains a server-side request forgery flaw that can expose internal network resources. Security researchers warn that once code execution is achieved on these servers, plaintext API keys and cloud credentials stored in environment variables — as recommended in most official setup guides — are trivially recoverable.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in