CVE-2026-48746
Critical · CVSS 9.1vLLM — HTTP Request Smuggling / Trust Boundary Violation Authentication Bypass (CWE-444, CWE-501)
- CVSS
- 9.1
- nvd
- EPSS
- 1.15%
- 64th pct
- KEV
- No
- Class
- oss containerizable
- CWE-444, CWE-501
Description
vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.
Search profile — drives PoC discovery
Symbols AuthenticationMiddlewareVLLM_API_KEY--api-keyASGIstarletteOpenAI APIopenai_servingapi_keyverify_api_keyX-Forwarded-Fortrusted_ipsProxyHeadersMiddleware
Keywords CVE-2026-48746vLLM authentication bypassvLLM ASGI AuthenticationMiddleware bypassvLLM VLLM_API_KEY bypassstarlette trust proxy header bypassvLLM OpenAI API key bypassGHSA-94f4-hr76-p5j6x41-2026-002-starlettevLLM CWE-444 CWE-501vLLM api-key bypass PoCvllm-project vllm authentication vulnerability
Versions: 0.3.0 to <0.22.0
Affected packages
| PyPI | vllm | 0.3.0 → 0.22.0 |
References
- https://github.com/vllm-project/vllm/pull/43426
- https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6
- https://x41-dsec.de/lab/advisories/x41-2026-002-starlette
- https://access.redhat.com/errata/RHSA-2026:30088
- https://access.redhat.com/errata/RHSA-2026:30089
- https://access.redhat.com/errata/RHSA-2026:36005
- https://access.redhat.com/errata/RHSA-2026:36006
- https://access.redhat.com/errata/RHSA-2026:42132
- https://access.redhat.com/errata/RHSA-2026:42142
- https://access.redhat.com/errata/RHSA-2026:42644
- https://access.redhat.com/errata/RHSA-2026:43038
- https://access.redhat.com/security/cve/CVE-2026-48746
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T18:30:14.000Z