CVE-2026-48746: CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in vllm-project vllm
vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.
AI Analysis
Technical Summary
CVE-2026-48746 is an authentication bypass vulnerability in vLLM, an inference and serving engine for large language models, affecting versions >=0.3.0 and <0.22.0. The flaw resides in ASGI web servers and Starlette's trust in them, allowing an attacker to craft a Host header that causes the OpenAI API AuthenticationMiddleware to check a different URL path than the one actually dispatched. This bypasses the configured VLLM_API_KEY or --api-key, enabling unauthorized access to the inference API. The vulnerability does not allow integrity compromise or arbitrary code execution but can lead to confidentiality loss (model and prompt abuse) and availability impact (resource exhaustion). Exploitation requires the API key authentication feature to be enabled and the service to be accessible without an RFC-conforming reverse proxy that normalizes the Host header. The vulnerability is fixed in vLLM version 0.22.0.
Potential Impact
Successful exploitation allows unauthorized inference API access without authentication, leading to confidentiality loss through model or prompt abuse and availability impact due to potential resource exhaustion. There is no impact on data integrity or code execution. The vulnerability requires network access to the vLLM endpoint and the API key authentication to be enabled. Deployments behind compliant reverse proxies that normalize the Host header are not vulnerable. Red Hat rates the impact as Important due to conditional deployment factors, while the CVSS score is 9.1 (critical).
Mitigation Recommendations
A patch is available in vLLM version 0.22.0 that fixes this authentication bypass vulnerability. Users should upgrade to version 0.22.0 or later. Additionally, restrict network access to the vLLM API endpoint to trusted clients and internal networks by implementing firewall rules or network policies to reduce exposure. Deploy the service behind an RFC-conforming reverse proxy that normalizes the Host header to prevent exploitation. These mitigations reduce the attack surface and prevent unauthorized access.
CVE-2026-48746: CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in vllm-project vllm
Description
vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.
CVSS v3.1
Score 9.1critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-48746 is an authentication bypass vulnerability in vLLM, an inference and serving engine for large language models, affecting versions >=0.3.0 and <0.22.0. The flaw resides in ASGI web servers and Starlette's trust in them, allowing an attacker to craft a Host header that causes the OpenAI API AuthenticationMiddleware to check a different URL path than the one actually dispatched. This bypasses the configured VLLM_API_KEY or --api-key, enabling unauthorized access to the inference API. The vulnerability does not allow integrity compromise or arbitrary code execution but can lead to confidentiality loss (model and prompt abuse) and availability impact (resource exhaustion). Exploitation requires the API key authentication feature to be enabled and the service to be accessible without an RFC-conforming reverse proxy that normalizes the Host header. The vulnerability is fixed in vLLM version 0.22.0.
Potential Impact
Successful exploitation allows unauthorized inference API access without authentication, leading to confidentiality loss through model or prompt abuse and availability impact due to potential resource exhaustion. There is no impact on data integrity or code execution. The vulnerability requires network access to the vLLM endpoint and the API key authentication to be enabled. Deployments behind compliant reverse proxies that normalize the Host header are not vulnerable. Red Hat rates the impact as Important due to conditional deployment factors, while the CVSS score is 9.1 (critical).
Mitigation Recommendations
A patch is available in vLLM version 0.22.0 that fixes this authentication bypass vulnerability. Users should upgrade to version 0.22.0 or later. Additionally, restrict network access to the vLLM API endpoint to trusted clients and internal networks by implementing firewall rules or network policies to reduce exposure. Deploy the service behind an RFC-conforming reverse proxy that normalizes the Host header to prevent exploitation. These mitigations reduce the attack surface and prevent unauthorized access.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_base
- Csaf Version
- 2.0
- Publisher
- Bundesamt für Sicherheit in der Informationstechnik
- Advisory Id
- WID-SEC-W-2026-1974
- Cve Count
- 1
Threat ID: 6a32cff89f87a2db092d9c1a
Added to database: 06/17/2026, 16:48:56 UTC
Last enriched: 08/11/2026, 12:53:48 UTC
Last updated: 09/14/2026, 22:49:09 UTC
Views: 371
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.