A One-Character Token Was Enough: LiteLLM and the Credential Concentration Problem in AI Gateways
A one-character bearer token was enough to bypass authentication in LiteLLM's MCP Streamable HTTP endpoint, tracked as CVE-2026-59822, because the OAuth2 header path returned an empty authentication o…