- Description
- vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.
- Source
- security-advisories@github.com
- NVD status
- Modified
- Products
- vllm
CVSS 3.1
- Type
- Secondary
- Base score
- 9.1
- Impact score
- 5.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- Severity
- CRITICAL
- Hype score
- Not currently trending
🚨 CRITICAL: CVE-2026-48746 (CVSS 9.1) - vLLM authentication bypass vulnerability affects versions 0.3.0-0.22.0. Attackers can access OpenAI API without API key. Patch to v0.22.0 immediately. #CVE #PatchNow #ThreatIntel https://t.co/x6e4drd5CG
@DFIR_Lab
23 Jun 2026
67 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-48746 vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those … https://t.co/iENM5Ocd6l ----- Traducción: CVE-2026-48746 vLL… https://t.co/utmtNg
@infoflowcloud
22 Jun 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "0D7B8DAA-6987-468A-9721-05A123DB61E3",
"versionEndExcluding": "0.22.0",
"versionStartIncluding": "0.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]