← All CVEs

CVE-2026-48746

critical · 9.1

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.

9.1
CVSS
1.2%
EPSS (exploit prob.)
66th
EPSS percentile
2026-06-22
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Weaknesses

CWE-444CWE-501

Affected products

VendorProductAffected versions
vllmvllm>= 0.3.0, < 0.22.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-48746