CVE-2026-48746Disclosure(vllm / vllm)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch vllm vllm systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444CWE-501

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vllm

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-06-22); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
vllm

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-06-16: 1Mentions · 2026-06-22: 2Mentions · 2026-06-23: 1Mentions · 2026-06-24: 1Active Exploitation · 2026-06-24: 1Patch / Workaround · 2026-06-16: 1Patch / Workaround · 2026-06-23: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-22: 2Technical Details · 2026-06-23: 106-1606-2206-2306-24
Signal classification4 categories
Disclosure
240.0%
General
120.0%
Patch
120.0%
Active Exploitation
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-161
Disclosure1
2026-06-222
Disclosure1General1
2026-06-231
Patch1
2026-06-241
Active Exploitation1
Full discourse5 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting vLLM (CVE-2026-48746) https://vuldb.com/vuln/372828/cti

    Post summary

    The post signals that elevated, potentially malicious activity has been observed against vLLM (CVE-2026-48746), indicating possible ongoing exploitation, but provides no proof of concept, exploit details, or mitigation information.

    00000131
    2.2K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-48746 (CVSS 9.1) - vLLM authentication bypass vulnerability affects versions 0.3.0-0.22.0. Attackers can access OpenAI API without API key. Patch to v0.22.0 immediately. #CVE #PatchNow #ThreatIntel https://t.co/x6e4drd5CG

    Post summary

    The tweet announces a critical authentication bypass flaw (CVE-2026‑48746) in vLLM, gives CVSS and version details, and urges an immediate patch to v0.22.0.

    0000081
    50 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-48746 vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those … https://www.cve.org/CVERecord?id=CVE-2026-48746 ----- Traducción: CVE-2026-48746 vLL… http://infoflow.cloud`

    Post summary

    The CVE-2026-48746 vulnerability affects vLLM's ASGI server integration up to version 0.22.0, with technical details available on the CVE record.

    0000037
    88 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-48746 vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those … https://www.cve.org/CVERecord?id=CVE-2026-48746

    Post summary

    The post briefly mentions CVE‑2026‑48746, noting its impact on vLLM 0.3.0–0.22.0 due to a flaw in ASGI servers and Starlette; it lacks details on exploits, patches, or active usage.

    00000674
    57.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Authentication Bypass in vLLM OpenAI API Middleware (CVE-2026-48746) vLLM's OpenAI API AuthenticationMiddleware can be bypassed due to improper trust in the reconstructed URL path from the ASGI scope. An attacker can manipulate the Host header to alter the parsed URL path used for authentication checks while maintaining access to protected routes through standard HTTP routing. This flaw allows unauthorized use of the API without an API key, posing a severe risk if the API is publicly exposed. 👉 Affected: vLLM >= 0.3.0, < 0.22.0 | fix 0.22.0

    Post summary

    vLLM's OpenAI API authentication bypass (CVE‑2026‑48746) permits unauthorized API use via Host header manipulation; no PoC or exploit code shared, but a patch (v0.22.0) is available.

    0000083
    217 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvllmvllm---

Explore more