This observation covers the period from 7:08 am on 4 October to 7:08 am on 5 October 2026 in Sydney, Australia. It includes one formally released and verifiable AI technology change.
LiteLLM 1.104.0: tighter default security boundaries for an AI gateway
LiteLLM released version 1.104.0 as a stable build at 10:50 pm UTC on 3 October, or 9:50 am Sydney time on 4 October. Its official container registry subsequently pointed the 1.104.0, v1.104.0, main-stable and latest tags to the same image digest. LiteLLM is an open-source AI gateway that exposes a common interface across multiple model providers. Compared with version 1.103.0, this release adds catalogue entries for models including Claude Opus 5.5 and the GPT-6 family, as well as team-priority routing, while also changing several default deployment and authentication behaviours.
The proxy now refuses to start when its master key is missing, empty or publicly known to be weak. An explicit weak-key override remains available, but the documentation labels it as dangerous. MCP servers using standard input and output are now disabled by default: existing configurations will not start and new ones are rejected unless LITELLM_ENABLE_MCP_STDIO=true is set in the process environment. The proxy exits when database initialisation or migration fails rather than continuing with a potentially outdated schema. Authentication now fails closed during a database outage, and signing out revokes the session. Budget exhaustion returns HTTP 422, distinguishing it from the 429 status used for rate limiting.
LiteLLM also supplies Cosign signatures for its Docker images and provides digest-based verification commands on the release page. The official notes list further changes to model support, routing, context compaction and provider affinity. These capability and security claims come from the developer's release documentation and inspectable package state. No public independent production evaluation currently quantifies the upgrade's reliability, security effectiveness or performance cost. Existing deployments that rely on a weak master key, stdio MCP or the former database start-up behaviour need configuration changes before upgrading.
PyPI published an incident report on 2 April 2026 documenting how malicious LiteLLM versions entered the package ecosystem. That report provides independent historical context for supply-chain risk in gateway software, but there is no evidence that every change in version 1.104.0 was directly caused by that incident, so no causal link is asserted here.
Sources
https://github.com/BerriAI/litellm/releases/tag/v1.104.0
https://docs.litellm.ai/release_notes/v1.104.0/v1-104-0
https://blog.pypi.org/posts/2026-04-02-incident-report-litellm-telnyx-supply-chain-attack/
Discover more from Geoffrey Chen
Subscribe to get the latest posts sent to your email.