Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2026-48746

около 1 месяца назад

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-48746

около 1 месяца назад

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-48746

около 1 месяца назад

vLLM is an inference and serving engine for large language models (LLM ...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-94f4-hr76-p5j6

около 2 месяцев назад

vLLM: OpenAI auth bypass

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-48746

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.

CVSS3: 9.1
1%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-48746

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.

CVSS3: 9.1
1%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-48746

vLLM is an inference and serving engine for large language models (LLM ...

CVSS3: 9.1
1%
Низкий
около 1 месяца назад
github логотип
GHSA-94f4-hr76-p5j6

vLLM: OpenAI auth bypass

CVSS3: 9.1
1%
Низкий
около 2 месяцев назад

Уязвимостей на страницу