CVE-2026-48746
vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- EPSS probability
- 1.15%
- CWE
- CWE-444
- Published
- 2026-06-22
- Last modified
- 2026-09-01
Affected products
- vllm-project vllm
Weakness type
Related vulnerabilities
- CVE-2026-81356 — Visual Studio Code Security Feature Bypass Vulnerability
- CVE-2026-19203 — A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty...
- CVE-2026-18540 — undici vulnerable to downstream response splitting via retry interceptor
- CVE-2026-84380 — HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
- CVE-2026-84363 — Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
- CVE-2026-78605 — Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Elasticsearch Leading to Information Disclosure
- CVE-2026-73812 — inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length
- CVE-2026-73276 — inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i