CVE-2026-48746

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-22 23:16

Updated : 2026-09-16 13:18


NVD link : CVE-2026-48746

Mitre link : CVE-2026-48746

CVE.ORG link : CVE-2026-48746


JSON object : View

Products Affected

vllm

  • vllm
CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CWE-501

Trust Boundary Violation