MEDIUM SEVERITYCONFIRMED

X-Forwarded-For multi-hop format fails exact-match IP allowlist

Package
litellm
Version
1.82.6
Verified
2026-03-28

Description

litellm's proxy auth uses the raw `X-Forwarded-For` header string in an exact-match allowlist check. The RFC 7239 multi-hop format `"1.2.3.4, 10.0.0.1"` does not match the allowlist entry `"1.2.3.4"`, blocking legitimate proxied requests. An attacker can also spoof a single-hop value.

Reproduction

allowed_ips = ['1.2.3.4']
raw_xff = '1.2.3.4, 10.0.0.1'   # RFC 7239 multi-hop
result = raw_xff not in allowed_ips  # True — legitimate request blocked
← All bugsScan your code →