CVE-2026-73555: CWE-209: Generation of Error Message Containing Sensitive Information in vllm-project vllm
vLLM versions prior to 0.26.0 have a vulnerability where malformed API requests cause error messages to leak sensitive internal information such as file paths, line numbers, OS username, home directory, Python version, and internal package structure. This occurs because the error handler converts validation exceptions to strings that include traceback details, which are insufficiently sanitized before being returned in HTTP responses. This information disclosure can aid attackers in fingerprinting the environment and crafting targeted exploits. The issue affects all POST endpoints accepting JSON bodies. A fix is available in vLLM 0.26.0 that changes the error handling to avoid leaking such details.
AI Analysis
Technical Summary
When vLLM receives malformed JSON requests, FastAPI raises a Pydantic RequestValidationError. The vLLM error handler converts this exception to a string including internal file paths and line numbers, which are returned in HTTP responses. The existing sanitization removes memory addresses but not file path and line number patterns, resulting in leakage of sensitive environment details such as OS username, home directory, Python version, internal package structure, and handler function names. This vulnerability affects all JSON POST endpoints and enables unauthenticated attackers to fingerprint the system and narrow attack surfaces. The issue was fixed by changing the error handler to construct error messages from structured error data rather than stringifying the exception, or alternatively by improving the sanitization regex.
Potential Impact
An unauthenticated attacker can obtain sensitive internal information including OS username, home directory path, virtual environment path, Python version, internal source file paths with line numbers, and handler function names. This information disclosure can facilitate targeted attacks by enabling precise version fingerprinting and reducing the attack surface. The vulnerability does not allow direct code execution or data modification but leaks environment details that aid attackers.
Mitigation Recommendations
A fix is available in vLLM version 0.26.0 that changes the validation exception handler to avoid returning traceback-style strings in error responses. Users should upgrade to vLLM 0.26.0 or later. Alternatively, deploying vLLM behind a reverse proxy that rewrites error responses to remove file paths can mitigate the issue but is fragile. No other mitigations are recommended as the root cause is addressed in the official fix.
CVE-2026-73555: CWE-209: Generation of Error Message Containing Sensitive Information in vllm-project vllm
Description
vLLM versions prior to 0.26.0 have a vulnerability where malformed API requests cause error messages to leak sensitive internal information such as file paths, line numbers, OS username, home directory, Python version, and internal package structure. This occurs because the error handler converts validation exceptions to strings that include traceback details, which are insufficiently sanitized before being returned in HTTP responses. This information disclosure can aid attackers in fingerprinting the environment and crafting targeted exploits. The issue affects all POST endpoints accepting JSON bodies. A fix is available in vLLM 0.26.0 that changes the error handling to avoid leaking such details.
CVSS v3.1
Score 5.3medium
Affected software
vllm-project
vllm
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
When vLLM receives malformed JSON requests, FastAPI raises a Pydantic RequestValidationError. The vLLM error handler converts this exception to a string including internal file paths and line numbers, which are returned in HTTP responses. The existing sanitization removes memory addresses but not file path and line number patterns, resulting in leakage of sensitive environment details such as OS username, home directory, Python version, internal package structure, and handler function names. This vulnerability affects all JSON POST endpoints and enables unauthenticated attackers to fingerprint the system and narrow attack surfaces. The issue was fixed by changing the error handler to construct error messages from structured error data rather than stringifying the exception, or alternatively by improving the sanitization regex.
Potential Impact
An unauthenticated attacker can obtain sensitive internal information including OS username, home directory path, virtual environment path, Python version, internal source file paths with line numbers, and handler function names. This information disclosure can facilitate targeted attacks by enabling precise version fingerprinting and reducing the attack surface. The vulnerability does not allow direct code execution or data modification but leaks environment details that aid attackers.
Mitigation Recommendations
A fix is available in vLLM version 0.26.0 that changes the validation exception handler to avoid returning traceback-style strings in error responses. Users should upgrade to vLLM 0.26.0 or later. Alternatively, deploying vLLM behind a reverse proxy that rewrites error responses to remove file paths can mitigate the issue but is fragile. No other mitigations are recommended as the root cause is addressed in the official fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-12T20:53:46.380Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7ddecdbf8831d5395d0179
Added to database: 08/13/2026, 15:12:13 UTC
Last enriched: 09/13/2026, 13:04:08 UTC
Last updated: 09/28/2026, 13:47:47 UTC
Views: 68
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.