Sync packaging to live v1.84.0 deployment (CVE-2026-35029/59822 fix line) #1

Closed
inference-bot wants to merge 0 commits from fix/cve-upgrade-v1.84.0-repo-sync into main
pull from: fix/cve-upgrade-v1.84.0-repo-sync
Owner

The gateway was upgraded to v1.84.0 in response to a member CVE report (CVE-2026-35029 fixed 1.83.0; CVE-2026-59822 fixed 1.84.0, CISA KEV). The upgrade attempt broke the gateway (floating tag moved digest mid-migration, slow prisma migration); it has now been repaired and is live. This PR syncs the repo to the deployed packaging.

Changes:

  • Dockerfile: pin ghcr.io/berriai/litellm:v1.84.0 (was floating main-v1.74.0-stable, which silently moved)
  • Remove v1.74.0-era sed CORS patch (upstream now reads LITELLM_CORS_ORIGINS natively)
  • start.sh: export LITELLM_CORS_ORIGINS instead of the old LITELLM_CORS_ALLOWED_ORIGINS
  • CloudronManifest: upstreamVersion -> 1.84.0

LITELLM_CORS_ORIGINS is also set as a Cloudron app env var so the running container honours it without a rebuild.

The gateway was upgraded to v1.84.0 in response to a member CVE report (CVE-2026-35029 fixed 1.83.0; CVE-2026-59822 fixed 1.84.0, CISA KEV). The upgrade attempt broke the gateway (floating tag moved digest mid-migration, slow prisma migration); it has now been repaired and is live. This PR syncs the repo to the deployed packaging. Changes: - Dockerfile: pin ghcr.io/berriai/litellm:v1.84.0 (was floating main-v1.74.0-stable, which silently moved) - Remove v1.74.0-era sed CORS patch (upstream now reads LITELLM_CORS_ORIGINS natively) - start.sh: export LITELLM_CORS_ORIGINS instead of the old LITELLM_CORS_ALLOWED_ORIGINS - CloudronManifest: upstreamVersion -> 1.84.0 LITELLM_CORS_ORIGINS is also set as a Cloudron app env var so the running container honours it without a rebuild.
inference-bot added 1 commit 2026-10-02 05:32:57 +00:00
- Dockerfile: pin ghcr.io/berriai/litellm:v1.84.0 (was floating
  main-v1.74.0-stable, which silently moved to a newer digest).
  v1.84.0 is the fix line for CVE-2026-35029 (auth bypass on
  /config/update, fixed 1.83.0) and CVE-2026-59822 (MCP session
  auth bypass, fixed 1.84.0, CISA KEV).
- Drop the v1.74.0-era sed CORS patch: upstream v1.84.0 moved the
  file and now reads LITELLM_CORS_ORIGINS natively.
- start.sh: export LITELLM_CORS_ORIGINS (the native v1.84.0 var)
  instead of LITELLM_CORS_ALLOWED_ORIGINS (the old sed-patch var
  that v1.84.0 ignores) — keeps CORS locked to chat.inference.coop.
- CloudronManifest: upstreamVersion 1.74.0 -> 1.84.0.

Live gateway already runs v1.84.0 (image digest
sha256:dc532d896ba8..., built 2026-10-02 04:50 UTC); this commit
makes the repo mirror the deployed packaging per the no-drift rule.
LITELLM_CORS_ORIGINS also set as a Cloudron env var on the app so
the running container honours it without a rebuild.
inference-bot added 1 commit 2026-10-02 06:52:54 +00:00
The 2026-10-02 outage had three causes the runbook now prevents:
- floating tag drift (README now mandates exact-tag pinning)
- 256MB default cgroup cap OOM-killing the prisma migration engine
  (manifest now sets memoryLimit: 2147483648)
- no _prisma_migrations ledger -> P3005 crash-loop on boot
  (start.sh now exports LITELLM_MIGRATION_DIR=/app/data/migrations)

README 'Updating LiteLLM' section rewritten from the old (wrong)
floating-tag procedure into a runbook with rules + verify checklist.
inference-bot closed this pull request 2026-10-02 06:59:27 +00:00

Pull request closed

Please reopen this pull request to perform a merge.
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: code/litellm#1