CVE-2026-48746

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*

History

22 Jul 2026, 12:18

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:43038 -

21 Jul 2026, 12:18

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:42132 -
  • () https://access.redhat.com/errata/RHSA-2026:42142 -
  • () https://access.redhat.com/errata/RHSA-2026:42644 -

07 Jul 2026, 12:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:36005 -
  • () https://access.redhat.com/errata/RHSA-2026:36006 -

30 Jun 2026, 03:20

Type Values Removed Values Added
CWE CWE-501
References
  • () https://access.redhat.com/errata/RHSA-2026:30088 -
  • () https://access.redhat.com/errata/RHSA-2026:30089 -
  • () https://access.redhat.com/security/cve/CVE-2026-48746 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2491581 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48746.json -

24 Jun 2026, 16:49

Type Values Removed Values Added
First Time Vllm
Vllm vllm
CPE cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*
References () https://github.com/vllm-project/vllm/pull/43426 - () https://github.com/vllm-project/vllm/pull/43426 - Issue Tracking
References () https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6 - () https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6 - Third Party Advisory
References () https://x41-dsec.de/lab/advisories/x41-2026-002-starlette - () https://x41-dsec.de/lab/advisories/x41-2026-002-starlette - Third Party Advisory

23 Jun 2026, 16:17

Type Values Removed Values Added
References
  • {'url': 'https://x41-dsec.de/lab/advisories/x41-2026-002-starlette/', 'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0'}
References () https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6 - () https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6 -
References () https://x41-dsec.de/lab/advisories/x41-2026-002-starlette - () https://x41-dsec.de/lab/advisories/x41-2026-002-starlette -

23 Jun 2026, 15:16

Type Values Removed Values Added
References
  • () https://x41-dsec.de/lab/advisories/x41-2026-002-starlette/ -
References () https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6 - () https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6 -

22 Jun 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-22 23:16

Updated : 2026-07-22 12:18


NVD link : CVE-2026-48746

Mitre link : CVE-2026-48746

CVE.ORG link : CVE-2026-48746


JSON object : View

Products Affected

vllm

  • vllm
CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CWE-501

Trust Boundary Violation