- CVSS
- CRITICAL · 9.1v3.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- Published
- 2026-06-22
- Weakness
- CWE-444, CWE-501
- Source
- nvd.nist.gov/vuln/detail/CVE-2026-48746
Description
vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette’s trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or –api-key. This vulnerability is fixed in 0.22.0.
References
- https://github.com/vllm-project/vllm/pull/43426
- https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6
- https://x41-dsec.de/lab/advisories/x41-2026-002-starlette
- https://access.redhat.com/errata/RHSA-2026:30088
- https://access.redhat.com/errata/RHSA-2026:30089
- https://access.redhat.com/security/cve/CVE-2026-48746
How GTK Cyber trains on this
AI security training at GTK Cyber covers the LLM and ML-pipeline vulnerability classes that vulnerabilities like CVE-2026-48746 fall into. Our hands-on courses are taught by Charles Givre and other practitioners who break and defend production AI systems.