5.3
CVE-2026-73555
- EPSS 0.26%
- Veröffentlicht 13.08.2026 14:50:03
- Zuletzt bearbeitet 14.08.2026 16:17:00
- CVE-Watchlists
- Unerledigt
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_message in vllm/entrypoints/utils.py does not remove traceback-style file paths, allowing unauthenticated malformed JSON requests to /v1/chat/completions, /v1/completions, /tokenize, and /detokenize to disclose the OS username, home and virtual-environment paths, Python version, internal package structure, line numbers, and endpoint handler names. This issue is fixed in version 0.26.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellervllm-project
≫
Produkt
vllm
Version
< 0.26.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.171 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-209 Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.
https://github.com/vllm-project/vllm/security/advisories/GHSA-hwrm-c4cx-rf4j
https://github.com/vllm-project/vllm/pull/46415
https://github.com/vllm-project/vllm/commit/e87521626febe2763f997691d1599de4175f4324
https://github.com/vllm-project/vllm/releases/tag/v0.26.0