CVE-2026-48746
CRITICAL 9.1vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.
Severe if exploited (CVSS 9.1), but no known exploitation and low modeled probability. Patch on a normal cadence.
Exploitation likelihood
0.9%chance of exploitation in 30 days · 54th percentile
Impact if exploited
9.1CVSS 3.1 · CRITICAL
- ConfidentialityHigh
- IntegrityNone
- AvailabilityHigh
What an attacker needs
- ✓Access: Reachable over the network — no local access needed
- ✓Privileges: No account or privileges required
- ✓User interaction: No user interaction needed
- ✓Complexity: No special conditions — reliably repeatable
✓ lowers the bar for an attacker · ⚠ raises it
Affected
Vendors Vllm Project Red Hat
Products Vllm Red Hat Ai Inference Server 3.3 Exploit Intelligence Migration Toolkit For Applications 8 Openshift Lightspeed Red Hat Ai Inference Server Red Hat Ansible Automation Platform 2 Red Hat Enterprise Linux Ai (Rhel Ai) 3
Weakness (CWE)
- CWE-444
- CWE-501
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
References
Advisories
Technical & other
- https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6
- https://github.com/vllm-project/vllm/pull/43426
- https://x41-dsec.de/lab/advisories/x41-2026-002-starlette
- https://access.redhat.com/security/cve/CVE-2026-48746
- https://bugzilla.redhat.com/show_bug.cgi?id=2491581
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48746.json