---
title: "v1.84.2 - Path-Handling Hardening Backport"
url: "/release_notes/v1.84.2/v1-84-2"
canonical_url: "https://docs.litellm.ai/release_notes/v1.84.2/v1-84-2"
type: "release-notes"
last_updated: "2026-10-09"
related:
  - "/release_notes/v1.84.3/v1-84-3"
  - "/release_notes/v1.84.1/v1-84-1"
---
# v1.84.2 - Path-Handling Hardening Backport

> Index of all LiteLLM docs: https://docs.litellm.ai/llms.txt

## Deploy this version

**Docker**

```bash
docker run \
-e STORE_MODEL_IN_DB=True \
-p 4000:4000 \
docker.litellm.ai/berriai/litellm:1.84.2
```

**Pip**

```bash
pip install litellm==1.84.2
```

`v1.84.2` is a patch release on top of [`v1.84.1`](/release_notes/v1.84.1/v1-84-1). It backports the path-handling hardening covered in the [host-header authentication bypass advisory](/blog/host-header-auth-bypass) and restores `npm` to the non-root Docker builder.

Non-root deployments should pin [`v1.84.3`](/release_notes/v1.84.3/v1-84-3) instead; the `litellm-non_root:1.84.2` image failed to build because `npm` was missing from the builder, and `v1.84.3` ships the same application code with a fixed `Dockerfile.non_root`.

### Bug Fixes

- **Proxy auth / routing**
    - Route the proxy's path-dependent call sites through `get_request_route()` so they all derive the request route from the ASGI scope rather than the `Host`-reconstructed URL - [PR #28547](https://github.com/BerriAI/litellm/pull/28547)

### Infrastructure

- **Docker**
    - Restore `npm` to the `Dockerfile.non_root` builder stage so `prisma-python` no longer falls back to a `nodeenv`-bootstrapped Node runtime. Applies to `v1.84.3` and later; the `litellm-non_root:1.84.2` image did not build - [PR #28519](https://github.com/BerriAI/litellm/pull/28519)

## Full Changelog

https://github.com/BerriAI/litellm/compare/v1.84.1...5560f35279

## Related pages

- [v1.84.3](https://docs.litellm.ai/release_notes/v1.84.3/v1-84-3.md)
- [v1.84.1](https://docs.litellm.ai/release_notes/v1.84.1/v1-84-1.md)
