{"id":"CVE-2025-48956","title":"vllm: HTTP header size limit not enforced allows Denial of Service from Unauthenticated requests (CVE-2025-48956)","summary":"A flaw was found in vLLM. A denial of service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large X-Forwarded-For header to an HTTP endpoint. This results in server memory exhaustion, potential…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-130","vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI)","affected":["ai_inference_server","enterprise_linux_ai_rhel_ai","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","enterprise_linux_ai 1.5","openshift_ai 2.25","openshift_ai 3.3"],"patched":["enterprise_linux_ai 1.5","openshift_ai 2.25","openshift_ai 3.3"],"published":"2025-08-26","updated":"2026-09-21","sourceUpdated":"2026-09-21T16:22:21+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-48956.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-48956.json"},{"url":"https://access.redhat.com/security/cve/CVE-2025-48956"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2372522"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-48956"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48956"},{"url":"https://github.com/vllm-project/vllm/commit/d8b736f913a59117803d6701521d2e4861701944"},{"url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-rxc4-3w6r-4v47"},{"url":"https://access.redhat.com/errata/RHSA-2025:19427"},{"url":"https://access.redhat.com/errata/RHSA-2025:19429"},{"url":"https://access.redhat.com/errata/RHSA-2025:19424"},{"url":"https://access.redhat.com/errata/RHSA-2025:19430"},{"url":"https://access.redhat.com/errata/RHSA-2025:19426"},{"url":"https://access.redhat.com/errata/RHSA-2025:19422"},{"url":"https://access.redhat.com/errata/RHSA-2025:19428"},{"url":"https://access.redhat.com/errata/RHSA-2025:19425"},{"url":"https://access.redhat.com/errata/RHSA-2025:19421"},{"url":"https://access.redhat.com/errata/RHSA-2025:19423"},{"url":"https://access.redhat.com/errata/RHSA-2026:24977"},{"url":"https://access.redhat.com/errata/RHSA-2026:3713"},{"url":"https://github.com/vllm-project/vllm/pull/23267"},{"url":"https://github.com/advisories/GHSA-rxc4-3w6r-4v47"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2021.yaml"},{"url":"https://github.com/vllm-project/vllm"},{"url":"https://pypi.org/project/vllm"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.0056,"epssPercentile":0.45461,"aliases":["GHSA-rxc4-3w6r-4v47","PYSEC-2026-2021"],"ecosystem":"pip","ingestedAt":"2026-07-08T18:25:53.039Z","slug":"CVE-2025-48956","body":"## Overview\n\nA flaw was found in vLLM. A denial of service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large X-Forwarded-For header to an HTTP endpoint. This results in server memory exhaustion, potentially leading to a crash or unresponsiveness. The attack does not require authentication, making it exploitable by any remote user.\n\n## Vendor advisories\n\n- **RHSA-2025:19427** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19427)\n- **RHSA-2025:19429** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19429)\n- **RHSA-2025:19424** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19424)\n- **RHSA-2025:19430** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19430)\n- **RHSA-2025:19426** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19426)\n- **RHSA-2025:19422** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19422)\n- **RHSA-2025:19428** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19428)\n- **RHSA-2025:19425** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19425)\n- **RHSA-2025:19421** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19421)\n- **RHSA-2025:19423** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19423)\n- **RHSA-2026:24977** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-06-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:24977)\n- **Red Hat VEX** · Important · affected: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI), Red Hat OpenShift AI (RHOAI) · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-48956.json)\n\n**vllm: HTTP header size limit not enforced allows Denial of Service from Unauthenticated requests** — rated Important by Red Hat. Released 2025-08-26, updated 2026-09-21.\n\nAffected:\n\n- Red Hat AI Inference Server\n- Red Hat Enterprise Linux AI (RHEL AI)\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n\nFixed:\n\n- Red Hat Enterprise Linux AI 1.5\n- Red Hat OpenShift AI 2.25\n- Red Hat OpenShift AI 3.3\n\nNo fix planned:\n\n- Red Hat AI Inference Server\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat Enterprise Linux AI (RHEL AI)\n- Red Hat OpenShift AI (RHOAI)\n\nNot affected:\n\n- Red Hat OpenShift AI 2.25\n- Red Hat OpenShift AI 3.3\n\n## Remediation\n\nFor more information visit https://access.redhat.com/errata/RHSA-2025:19427 https://access.redhat.com/errata/RHSA-2025:19427\nFor more information visit https://access.redhat.com/errata/RHSA-2025:19429 https://access.redhat.com/errata/RHSA-2025:19429\nFor more information visit https://access.redhat.com/errata/RHSA-2025:19424 https://access.redhat.com/errata/RHSA-2025:19424\n\nWorkarounds / mitigations:\n\n- Until a fix is available, the risk can be reduced by running vLLM behind a reverse proxy such as Nginx, Envoy, or HAProxy with strict header size limits, ensuring that oversized requests are dropped before reaching the service. Additional safeguards like container or VM resource limits and traffic monitoring can help contain the impact, but upgrading to the patched release remains the definitive solution.\n\n## Package advisory (CVE-2025-48956)\n\nAffected packages:\n\n- `vllm >= 0.1.0, < 0.10.1.1`\n\nPatched in:\n\n- `vllm 0.10.1.1`\n\nSource: https://osv.dev/vulnerability/GHSA-rxc4-3w6r-4v47","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}