DFIR Lab[verified]@DFIR_LabPatch
The tweet announces a critical authentication bypass flaw (CVE-2026‑48746) in vLLM, gives CVSS and version details, and urges an immediate patch to v0.22.0.
Upwind Security MDR[verified]@UpwindMDRDisclosure
vLLM's OpenAI API authentication bypass (CVE‑2026‑48746) permits unauthorized API use via Host header manipulation; no PoC or exploit code shared, but a patch (v0.22.0) is available.
VulDB 🛡@vuldbActive Exploitation
The post signals that elevated, potentially malicious activity has been observed against vLLM (CVE-2026-48746), indicating possible ongoing exploitation, but provides no proof of concept, exploit details, or mitigation information.
Infoflowcloud@infoflowcloudDisclosure
The CVE-2026-48746 vulnerability affects vLLM's ASGI server integration up to version 0.22.0, with technical details available on the CVE record.
CVE@CVEnewGeneral
The post briefly mentions CVE‑2026‑48746, noting its impact on vLLM 0.3.0–0.22.0 due to a flaw in ASGI servers and Starlette; it lacks details on exploits, patches, or active usage.