# CVE-2024-9606

## Summary

- **CVE ID:** CVE-2024-9606
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-117
- **Published:** Mar 20, 2025
- **Last Modified:** Mar 13, 2026

## Description

In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerability where the API key masking code only masks the first 5 characters of the key. This results in the leakage of almost the entire API key in the logs, exposing a significant amount of the secret key. The issue affects version v1.44.9.

## Affected Products

- berriai — berriai/litellm (unspecified)

## References

- [CNA](https://huntr.com/bounties/4a03796f-a8d4-4293-84ef-d3959456223a)
- [CNA](https://github.com/berriai/litellm/commit/9094071c4782183e84f10630e2450be3db55509a)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.74%
- **EPSS Percentile:** 52.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._