CVE-2026-24779Disclosure(vllm / vllm)

LOWCVSS 7.1 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch vllm vllm systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability exists in the `MediaConnector` class within the vLLM project's multimodal feature set. The load_from_url and load_from_url_async methods obtain and process media from URLs provided by users, using different Python parsing libraries when restricting the target host. These two parsing libraries have different interpretations of backslashes, which allows the host name restriction to be bypassed. This allows an attacker to coerce the vLLM server into making arbitrary requests to internal network resources. This vulnerability is particularly critical in containerized environments like `llm-d`, where a compromised vLLM pod could be used to scan the internal network, interact with other pods, and potentially cause denial of service or access sensitive data. For example, an attacker could make the vLLM pod send malicious requests to an internal `llm-d` management endpoint, leading to system instability by falsely reporting metrics like the KV cache state. Version 0.14.1 contains a patch for the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vllm

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-01-28); latest day: 2
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
vllm

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-01-27: 1Mentions · 2026-01-28: 2Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1Mentions · 2026-06-05: 2PoC Mentioned / Linked · 2026-06-05: 1Patch / Workaround · 2026-01-27: 1Patch / Workaround · 2026-01-28: 1Technical Details · 2026-01-27: 1Technical Details · 2026-01-28: 2Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 101-2701-2803-0903-1006-05
Signal classification3 categories
Disclosure
457.1%
General
228.6%
PoC
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-01-271
Disclosure1
2026-01-282
Disclosure2
2026-03-091
General1
2026-03-101
Disclosure1
2026-06-052
General1PoC1
Full discourse7 posts
  • SRG@SimeonGarratt
    General

    @PsudoMike The satirical part is - their core infra/backend is already completely vulnerable and exposed. And it hasn't even started. (CVE-2026-22778), (CVE-2026-24779)... for starters.

    Post summary

    The post merely states that two CVEs might be real, with no evidence of exploitation, remediation, or technical detail.

    10000772
    1.3K followersView on X
  • SRG@SimeonGarratt
    PoC

    @RealNicoLagan Bumping this b/c 🙏 "Canada's 'big plan' is sitting with core infra/backend already completely vulnerable and exposed. If the govt is serious [PoC] (CVE-2026-22778), (CVE-2026-24779)... for starters."

    Post summary

    The tweet indicates that proof‑of‑concepts for CVE‑2026‑22778 and CVE‑2026‑24779 are available and that Canadian core infrastructure is reportedly vulnerable.

    0000066
    1.3K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 vLLM, SSRF Bypass, #CVE-2026-24779 (High) https://dailycve.com/vllm-ssrf-bypass-cve-2026-24779-high/

    Post summary

    The tweet announces the newly disclosed vulnerability CVE‑2026‑24779, describing it as an SSRF bypass with high severity, and links to a CVE article for more details.

    0000038
    166 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25960 vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in the load_from_ur… https://www.cve.org/CVERecord?id=CVE-2026-25960

    Post summary

    The post references CVE‑2026‑25960 and notes a bypass of SSRF protection added for a related CVE, but it provides no evidence of a PoC, exploit, active exploitation, patch, or false‑positive claim.

    0000074
    56.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-24779: Schrödinger's URL: Breaking vLLM with Parser Differentials (CVE-2026-24779) A critical Server-Side Request Forgery (SSRF) vulnerability exists in vLLM versions prior to 0.14.1. The flaw stems from a 'Parser Differential' where the vali... https://cvereports.com/reports/CVE-2026-24779

    Post summary

    A critical SSRF vulnerability (CVE‑2026‑24779) affecting vLLM versions prior to 0.14.1 is disclosed with technical details, but no PoC, exploit, or evidence of active exploitation is presented.

    0000046
    29 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24779 Server-Side Request Forgery in vLLM Multimodal Feature via URL Parsing Bypass https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24779

    Post summary

    CVE-2026-24779 is a Server‑Side Request Forgery flaw in the vLLM multimodal feature that allows URL parsing bypass.

    0000064
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24779 vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability exists in the `M… https://www.cve.org/CVERecord?id=CVE-2026-24779

    Post summary

    The text announces a Server‑Side Request Forgery vulnerability in vLLM versions before 0.14.1, referencing the CVE record and indicating that newer releases contain the fix.

    00000209
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvllmvllm---

Explore more