{"id":"ECHO-979c-ccdf-dda8","summary":"Resolved by package bump to 1.90.0+e1 (fixed version: 1.83.7)","modified":"2026-09-15T03:33:35.508207412Z","published":"2026-05-17T15:00:06.121473Z","withdrawn":"2026-06-28T14:21:35.585Z","upstream":["CVE-2026-42208","GHSA-r75f-5x8p-qvmc"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/GHSA-r75f-5x8p-qvmc"},{"type":"WEB","url":"https://github.com/advisories/GHSA-r75f-5x8p-qvmc"}],"affected":[{"package":{"name":"litellm","ecosystem":"Echo:PyPI","purl":"pkg:pypi/litellm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.83.7"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-979c-ccdf-dda8.json"}}],"schema_version":"1.9.0"}