vLLM是vLLM团队开源的一个适用于 LLM 的高吞吐量和内存高效推理和服务引擎。 vLLM 0.23.1rc0之前版本存在日志信息泄露漏洞,该漏洞源于sanitize_message清理消息的辅助函数不完整,导致多个响应路径直接向客户端输出异常消息,且Anthropic API路由器、Server-Sent Events流转换器和实时语音转文本WebSocket处理路径绕过了全局FastAPI异常处理器,可能造成未经验证的攻击者通过发送损坏的图像字节泄露堆内存地址。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| vllm-project | vllm | < 0.23.1rc0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vllm-project | vllm | < 0.23.1rc0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | vLLM <= 0.23.0 incompletely fixes CVE-2026-22778. The original fix added sanitize_message to the OpenAI router but the Anthropic-compatible router (/v1/messages) echoes str(exc) directly. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-54236.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-48746 | 9.1 CRITICAL | vLLM: OpenAI auth bypass |
| CVE-2026-54232 | 8.8 HIGH | vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile |
| CVE-2026-41523 | 7.5 HIGH | vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arb |
| CVE-2026-47155 | 6.5 MEDIUM | vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, |
| CVE-2026-54233 | 6.5 MEDIUM | vLLM: OOM Denial of Service via Audio Decompression Bomb |
| CVE-2026-53923 | vLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overfl | |
| CVE-2026-54235 | vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kern |
No comments yet