CVE-2026-48746Critical· 9.1▾ AbyssalPoC availablevLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API Authenti…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 50.1 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.9%
0.9% → 1.2%
Last analysed / modified upstream
Exploit / PoC code exists
vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.
vllm >= 0.3.0, < 0.22.0Upgrade past the affected range:
vllm 0.22.0Affected packages:
vllm >= 0.3.0, < 0.22.0Patched in:
vllm 0.22.0Source: https://osv.dev/vulnerability/GHSA-94f4-hr76-p5j6
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73556Medium· 5.3vLLM is an inference and serving engine for large language models
CVE-2026-69147Medium· 6.5vLLM is an inference and serving engine for large language models
CVE-2026-22807High· 8.8vLLM is an inference and serving engine for large language models (LLMs)
CVE-2026-48710Medium· 6.5Starlette is a lightweight ASGI framework/toolkit
CVE-2026-22778Critical· 9.8vLLM is an inference and serving engine for large language models (LLMs)
CVE-2026-57173Medium· 6.5vLLM is an inference and serving engine for large language models