CVE-2026-73555

⚪ Do wiadomości

Błąd w vLLM umożliwia ujawnienie informacji o systemie operacyjnym przez nieautoryzowane żądania.

CVSS
5.3
EPSS
0.4%
Exploit
none
Vendor
vllm
Opis źródłowy (NVD)

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_message in vllm/entrypoints/utils.py does not remove traceback-style file paths, allowing unauthenticated malformed JSON requests to /v1/chat/completions, /v1/completions, /tokenize, and /detokenize to disclose the OS username, home and virtual-environment paths, Python version, internal package structure, line numbers, and endpoint handler names. This issue is fixed in version 0.26.0.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2026-08-13 15:20:17 UTC
Ostatnia modyfikacja (NVD)2026-10-02 19:28:34 UTC
Referencje