CVE-2025-59425High· 7.5▾ TwilightA flaw was found in vLLM’s API token authentication logic, where token comparisons were not performed in constant time. This weakness could allow an attacker to exploit timing differences to guess valid tokens and bypass authentication.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.5%
0.5% → 0.6%
Last analysed / modified upstream
A flaw was found in vLLM’s API token authentication logic, where token comparisons were not performed in constant time. This weakness could allow an attacker to exploit timing differences to guess valid tokens and bypass authentication.
vllm: Timing Attack in vLLM API Token Verification Leading to Authentication Bypass — rated Important by Red Hat. Released 2025-10-07, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
For more information visit https://access.redhat.com/errata/RHSA-2025:23080 https://access.redhat.com/errata/RHSA-2025:23080 For more information visit https://access.redhat.com/errata/RHSA-2025:23078 https://access.redhat.com/errata/RHSA-2025:23078 For more information visit https://access.redhat.com/errata/RHSA-2026:3461 https://access.redhat.com/errata/RHSA-2026:3461
Workarounds / mitigations:
Affected packages:
vllm < 0.11.0Patched in:
vllm 0.11.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-66448High· 7.5vllm: vLLM: Remote Code Execution via malicious model configuration (CVE-2025-66448)
CVE-2026-69247Medium· 5.9cryptography is a package designed to expose cryptographic primitives and recipes to Python developers
CVE-2026-54411Medium· 5.9Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeate…
CVE-2026-95897Medium· 5.5A security vulnerability has been detected in Dask up to 2026.8.0
CVE-2026-13087High· 8.8A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c
CVE-2026-94640High· 7.5A flaw was found in rpcbind