
@rez0__ @sshell_ @Cloudflare @hash_kitten @SLCyberSec @infosec_au Prob just salty this got dropped at 5pm EST on a Friday. 🤷
English
Nate Robb
659 posts

@NateRobb
Senior Threat Enablement Operator @BishopFox



This Strapi bug is a great example of how small trust-boundary mistakes become major security problems.

A failed login should not take 6 seconds. Bishop Fox researchers reproduced CVE-2026-42208 in LiteLLM’s proxy. The attack requires no authentication, still returns HTTP 401 responses, and uses timing delays to extract sensitive data. Observed in the wild roughly 36 hours after disclosure. Upgrade to 1.83.7 or higher.
















