CVE-2026-73555Active Exploitation

LOWCVSS 5.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_message in vllm/entrypoints/utils.py does not remove traceback-style file paths, allowing unauthenticated malformed JSON requests to /v1/chat/completions, /v1/completions, /tokenize, and /detokenize to disclose the OS username, home and virtual-environment paths, Python version, internal package structure, line numbers, and endpoint handler names. This issue is fixed in version 0.26.0.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-209

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-13); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-13: 1Mentions · 2026-09-05: 1Active Exploitation · 2026-08-13: 1Technical Details · 2026-08-13: 1Technical Details · 2026-09-05: 108-1309-05
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-131
Active Exploitation1
2026-09-051
Disclosure1
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 vLLM, Information Disclosure via Error Messages, #CVE-2026-73555 (Medium) -DC-Sep2026-2208 https://dailycve.com/vllm-information-disclosure-via-error-messages-cve-2026-73555-medium-dc-sep2026-2208/

    Post summary

    A disclosure article announces CVE-2026-73555 affecting vLLM, detailing an information disclosure via error messages with no evidence of exploitation or mitigation.

    0000049
    234 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    ⚠️ HIGH — CVE-2026-73555 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in… CVSS 5.3 ⚡ Exploit in the wild Full analysis → https://sec.kaitan.id/cves/CVE-2026-73555 #OpenAI #CyberSecurity #InfoSec

    Post summary

    CVE‑2026‑73555 is reported as actively exploited in the wild; while no PoC or exploit code is linked, the post provides technical context such as a CVSS score of 5.3 and affected component details.

    0000043
    88 followersView on X

Explore more