---
id: CVE-2025-59425
title: >-
  vllm: Timing Attack in vLLM API Token Verification Leading to Authentication
  Bypass (CVE-2025-59425)
summary: >-
  A flaw was found in vLLM’s API token authentication logic, where token
  comparisons were not performed in constant time. This weakness could allow an
  attacker to exploit timing differences to guess valid tokens and bypass
  authentication.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cvssSource: vendor
cwe: CWE-208
vendor: Red Hat
product: Red Hat OpenShift AI 3.3
affected:
  - ai_inference_server
  - enterprise_linux_ai_rhel_ai
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - ai_inference_server 3.2
  - openshift_ai 2.25
  - openshift_ai 3.3
patched:
  - ai_inference_server 3.2
  - openshift_ai 2.25
  - openshift_ai 3.3
published: '2025-10-07'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T15:31:11+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59425.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59425.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-59425'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2397234'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-59425'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59425'
  - url: >-
      https://github.com/vllm-project/vllm/commit/ee10d7e6ff5875386c7f136ce8b5f525c8fcef48
  - url: >-
      https://github.com/vllm-project/vllm/security/advisories/GHSA-wr9h-g72x-mwhm
  - url: 'https://access.redhat.com/errata/RHSA-2025:23080'
  - url: 'https://access.redhat.com/errata/RHSA-2025:23078'
  - url: 'https://access.redhat.com/errata/RHSA-2026:3461'
  - url: 'https://access.redhat.com/errata/RHSA-2026:3462'
  - url: 'https://access.redhat.com/errata/RHSA-2025:23079'
  - url: 'https://access.redhat.com/errata/RHSA-2026:3782'
  - url: 'https://access.redhat.com/errata/RHSA-2026:3713'
  - url: 'https://github.com/advisories/GHSA-wr9h-g72x-mwhm'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2026.yaml
  - url: 'https://github.com/vllm-project/vllm'
  - url: >-
      https://github.com/vllm-project/vllm/blob/4b946d693e0af15740e9ca9c0e059d5f333b1083/vllm/entrypoints/openai/api_server.py#L1270-L1274
  - url: 'https://github.com/vllm-project/vllm/releases/tag/v0.11.0'
  - url: 'https://pypi.org/project/vllm'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00566
epssPercentile: 0.44633
aliases:
  - GHSA-wr9h-g72x-mwhm
  - PYSEC-2026-2026
ecosystem: pip
ingestedAt: '2026-07-08T18:25:53.896Z'
---

## Overview

A flaw was found in vLLM’s API token authentication logic, where token comparisons were not performed in constant time. This weakness could allow an attacker to exploit timing differences to guess valid tokens and bypass authentication.

## Vendor advisories

- **RHSA-2025:23080** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2025-12-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:23080)
- **RHSA-2025:23078** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2025-12-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:23078)
- **RHSA-2026:3461** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-02-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:3461)
- **RHSA-2026:3462** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-02-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:3462)
- **RHSA-2025:23079** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2025-12-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:23079)
- **RHSA-2026:3782** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-03-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:3782)
- **RHSA-2026:3713** · Red Hat · fixed in: Red Hat OpenShift AI 3.3 · released 2026-03-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:3713)
- **Red Hat VEX** · Important · affected: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59425.json)

**vllm: Timing Attack in vLLM API Token Verification Leading to Authentication Bypass** — rated Important by Red Hat. Released 2025-10-07, updated 2026-09-21.

Affected:

- Red Hat AI Inference Server
- Red Hat Enterprise Linux AI (RHEL AI)
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)

Fixed:

- Red Hat AI Inference Server 3.2
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.3

No fix planned:

- Red Hat AI Inference Server
- Red Hat Enterprise Linux AI (RHEL AI)
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)

Not affected:

- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.3

## Remediation

For more information visit https://access.redhat.com/errata/RHSA-2025:23080 https://access.redhat.com/errata/RHSA-2025:23080
For more information visit https://access.redhat.com/errata/RHSA-2025:23078 https://access.redhat.com/errata/RHSA-2025:23078
For more information visit https://access.redhat.com/errata/RHSA-2026:3461 https://access.redhat.com/errata/RHSA-2026:3461

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2025-59425)

Affected packages:

- `vllm < 0.11.0`

Patched in:

- `vllm 0.11.0`

Source: https://osv.dev/vulnerability/GHSA-wr9h-g72x-mwhm
