---
id: CVE-2025-48956
title: >-
  vllm: HTTP header size limit not enforced allows Denial of Service from
  Unauthenticated requests (CVE-2025-48956)
summary: >-
  A flaw was found in vLLM. A denial of service (DoS) vulnerability can be
  triggered by sending a single HTTP GET request with an extremely large
  X-Forwarded-For header to an HTTP endpoint. This results in server memory
  exhaustion, potential…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-130
vendor: Red Hat
product: Red Hat Enterprise Linux AI (RHEL AI)
affected:
  - ai_inference_server
  - enterprise_linux_ai_rhel_ai
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - enterprise_linux_ai 1.5
  - openshift_ai 2.25
  - openshift_ai 3.3
patched:
  - enterprise_linux_ai 1.5
  - openshift_ai 2.25
  - openshift_ai 3.3
published: '2025-08-26'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T16:22:21+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-48956.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-48956.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-48956'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2372522'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-48956'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48956'
  - url: >-
      https://github.com/vllm-project/vllm/commit/d8b736f913a59117803d6701521d2e4861701944
  - url: >-
      https://github.com/vllm-project/vllm/security/advisories/GHSA-rxc4-3w6r-4v47
  - url: 'https://access.redhat.com/errata/RHSA-2025:19427'
  - url: 'https://access.redhat.com/errata/RHSA-2025:19429'
  - url: 'https://access.redhat.com/errata/RHSA-2025:19424'
  - url: 'https://access.redhat.com/errata/RHSA-2025:19430'
  - url: 'https://access.redhat.com/errata/RHSA-2025:19426'
  - url: 'https://access.redhat.com/errata/RHSA-2025:19422'
  - url: 'https://access.redhat.com/errata/RHSA-2025:19428'
  - url: 'https://access.redhat.com/errata/RHSA-2025:19425'
  - url: 'https://access.redhat.com/errata/RHSA-2025:19421'
  - url: 'https://access.redhat.com/errata/RHSA-2025:19423'
  - url: 'https://access.redhat.com/errata/RHSA-2026:24977'
  - url: 'https://access.redhat.com/errata/RHSA-2026:3713'
  - url: 'https://github.com/vllm-project/vllm/pull/23267'
  - url: 'https://github.com/advisories/GHSA-rxc4-3w6r-4v47'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2021.yaml
  - url: 'https://github.com/vllm-project/vllm'
  - url: 'https://pypi.org/project/vllm'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.0056
epssPercentile: 0.44212
aliases:
  - GHSA-rxc4-3w6r-4v47
  - PYSEC-2026-2021
ecosystem: pip
ingestedAt: '2026-07-08T18:25:53.039Z'
---

## Overview

A flaw was found in vLLM. A denial of service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large X-Forwarded-For header to an HTTP endpoint. This results in server memory exhaustion, potentially leading to a crash or unresponsiveness. The attack does not require authentication, making it exploitable by any remote user.

## Vendor advisories

- **RHSA-2025:19427** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19427)
- **RHSA-2025:19429** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19429)
- **RHSA-2025:19424** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19424)
- **RHSA-2025:19430** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19430)
- **RHSA-2025:19426** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19426)
- **RHSA-2025:19422** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19422)
- **RHSA-2025:19428** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19428)
- **RHSA-2025:19425** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19425)
- **RHSA-2025:19421** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19421)
- **RHSA-2025:19423** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-11-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:19423)
- **RHSA-2026:24977** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-06-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:24977)
- **Red Hat VEX** · Important · affected: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI), Red Hat OpenShift AI (RHOAI) · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-48956.json)

**vllm: HTTP header size limit not enforced allows Denial of Service from Unauthenticated requests** — rated Important by Red Hat. Released 2025-08-26, updated 2026-09-21.

Affected:

- Red Hat AI Inference Server
- Red Hat Enterprise Linux AI (RHEL AI)
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)

Fixed:

- Red Hat Enterprise Linux AI 1.5
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.3

No fix planned:

- Red Hat AI Inference Server
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Enterprise Linux AI (RHEL AI)
- Red Hat OpenShift AI (RHOAI)

Not affected:

- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.3

## Remediation

For more information visit https://access.redhat.com/errata/RHSA-2025:19427 https://access.redhat.com/errata/RHSA-2025:19427
For more information visit https://access.redhat.com/errata/RHSA-2025:19429 https://access.redhat.com/errata/RHSA-2025:19429
For more information visit https://access.redhat.com/errata/RHSA-2025:19424 https://access.redhat.com/errata/RHSA-2025:19424

Workarounds / mitigations:

- Until a fix is available, the risk can be reduced by running vLLM behind a reverse proxy such as Nginx, Envoy, or HAProxy with strict header size limits, ensuring that oversized requests are dropped before reaching the service. Additional safeguards like container or VM resource limits and traffic monitoring can help contain the impact, but upgrading to the patched release remains the definitive solution.

## Package advisory (CVE-2025-48956)

Affected packages:

- `vllm >= 0.1.0, < 0.10.1.1`

Patched in:

- `vllm 0.10.1.1`

Source: https://osv.dev/vulnerability/GHSA-rxc4-3w6r-4v47
