Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-48746

Опубликовано: 22 июн. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*
Версия от 0.3.0 (включая) до 0.22.0 (исключая)

EPSS

Процентиль: 59%
0.01014
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-444
CWE-501

Связанные уязвимости

CVSS3: 9.1
redhat
около 1 месяца назад

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.

CVSS3: 9.1
debian
около 1 месяца назад

vLLM is an inference and serving engine for large language models (LLM ...

CVSS3: 9.1
github
около 2 месяцев назад

vLLM: OpenAI auth bypass

EPSS

Процентиль: 59%
0.01014
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-444
CWE-501