{"slug": "the-ai-gateway-becomes-a-target-measuring-litellm-and-kestra-exposure", "title": "The AI Gateway Becomes a Target: Measuring LiteLLM and Kestra Exposure", "summary": "A security analysis found that LiteLLM, an AI gateway tied to CVE-2026-59822 (CVSS 8.8), had 34,412 internet-facing deployments, while workflow orchestration platform Kestra, affected by CVE-2026-49869 (CVSS 10.0), had 126, after both were added to CISA's Known Exploited Vulnerabilities catalog on September 2, 2026. The counts, gathered with ZoomEye on 2026-09-19, highlight that AI infrastructure components now hold high-value credentials such as model provider API keys and database secrets. The analysis recommends organizations query for their own AI gateways and orchestration tools to confirm none are unexpectedly exposed.", "body_md": "The CISA Known Exploited Vulnerabilities catalog update on September 2, 2026, marked a shift. Among the seven newly listed flaws were vulnerabilities in LiteLLM, an AI gateway, and Kestra, a workflow orchestration platform. For the first time, AI infrastructure components appeared as confirmed exploitation targets alongside traditional VPN and web-framework flaws. That makes their internet exposure worth measuring.\n\nLiteLLM (CVE-2026-59822, an improper authentication flaw rated CVSS 8.8) and Kestra (CVE-2026-49869, an OS command injection rated CVSS 10.0) are not edge appliances in the traditional sense. They are application-layer services that organizations deploy to route model requests and orchestrate data workflows. Because they often hold API keys to large language models and other sensitive services, a compromise can expose credentials rather than just compute.\n\nThe counts below were collected with ZoomEye on 2026-09-19 using sub_type \"all\" and a page size of one, so each figure is the matched total. Query strings are included for reproducibility. These counts describe internet-facing assets matching a fingerprint, not confirmed vulnerable instances.\n\n`app=\"LiteLLM\"` returned 34,412 matches, indicating a substantial number of internet-facing AI gateway deployments.`app=\"Kestra\"` returned 126 matches, a much smaller footprint consistent with a more specialized orchestration tool.`app=\"Langflow\"` returned 18,448 matches, another AI-adjacent platform with meaningful exposure.`app=\"Metabase\"` returned 115,725 matches, a widely deployed analytics tool that has also appeared in exploitation reporting.\nThe contrast between the AI-infrastructure counts is instructive. LiteLLM's larger footprint reflects how commonly AI gateways are deployed as shared services, often reachable by many internal clients and, in some cases, the internet. Kestra's smaller count does not make it less dangerous; a single exposed orchestration platform with command-execution potential is a serious risk.\nAI infrastructure deserves the same exposure discipline as traditional services. These platforms frequently hold high-value secrets: model provider API keys, database credentials, and workflow tokens. When such a service is internet-reachable and unpatched, the consequence is not just service disruption but credential theft at scale.\n\nThe measurement supports a concrete workflow. An organization can query for its AI gateways and orchestration tools, compare the result to its inventory, and verify that none of them are exposed to the public internet. Any match that the organization did not expect is an immediate finding.", "url": "https://wpnews.pro/news/the-ai-gateway-becomes-a-target-measuring-litellm-and-kestra-exposure", "canonical_source": "https://dev.to/kozhevniko/the-ai-gateway-becomes-a-target-measuring-litellm-and-kestra-exposure-2jb9", "published_at": "2026-09-18 22:20:07+00:00", "updated_at": "2026-09-18 22:52:53.404137+00:00", "lang": "en", "topics": ["ai-infrastructure", "ai-safety", "ai-policy", "ai-tools"], "entities": ["LiteLLM", "Kestra", "CISA", "ZoomEye", "Langflow", "Metabase", "CVE-2026-59822", "CVE-2026-49869"], "alternates": {"html": "https://wpnews.pro/news/the-ai-gateway-becomes-a-target-measuring-litellm-and-kestra-exposure", "markdown": "https://wpnews.pro/news/the-ai-gateway-becomes-a-target-measuring-litellm-and-kestra-exposure.md", "text": "https://wpnews.pro/news/the-ai-gateway-becomes-a-target-measuring-litellm-and-kestra-exposure.txt", "jsonld": "https://wpnews.pro/news/the-ai-gateway-becomes-a-target-measuring-litellm-and-kestra-exposure.jsonld"}}