<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:34:15.816086+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-369283</id>
    <title>EUVD-2026-369283</title>
    <updated>2026-10-02T22:34:16.300904+00:00</updated>
    <content>EUVD-2026-369283</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-369283"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48746</id>
    <title>fkie_cve-2026-48746</title>
    <updated>2026-10-02T22:34:16.300972+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48746"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-94f4-hr76-p5j6</id>
    <title>GHSA-94f4-hr76-p5j6 — vLLM: OpenAI auth bypass</title>
    <updated>2026-10-02T22:34:16.301011+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vllm</p>
<p>### Summary</p>
<p>A vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API `AuthenticationMiddleware`, which was discovered during @x41sec's source code audit.
It allows to use the API without providing the configured `VLLM_API_KEY` or `--api-key`.</p>
<p>### Details</p>
<p>In https://github.com/vllm-project/vllm/blob/v0.14.0/vllm/entrypoints/openai/api_server.py#L689-L692 the `url_path` is taken from the `URL`, which is reconstructed by _starlette_ based on the request `scope`.</p>
<p>```py
from starlette.datastructures import URL, Headers, MutableHeaders, State</p>
<p># ...</p>
<p>url_path = URL(scope=scope).path.removeprefix(root_path)
headers = Headers(scope=scope)
if url_path.startswith("/v1") and not self.verify_token(headers):
    response = JSONResponse(content={"error": "Unauthorized"}, status_code=401)
    return response(scope, receive, send)
return self.app(scope, receive, send)
```</p>
<p>The request `scope` includes the request's `Host:` header and reconstructs the URL as shown below:</p>
<p>```py
f"{scheme}://{host_header}{path}"
```</p>
<p>Neither starlette nor [any of the ASGI servers](https://asgi.readthedocs.io/en/latest/implementations.html#servers) (including uvicorn, which vllm uses) properly filter the `Host:` header for invalid characters. This allows an attacker to include special URL characters such as `/` or `?` in the `Host:` header and thereby control the reconstructed URL and it's `.path` attribute.</p>
<p>FastAPI/starlette's routi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-94f4-hr76-p5j6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-226</id>
    <title>PYSEC-2026-226</title>
    <updated>2026-10-02T22:34:16.301062+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vllm</p>
<p>vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-226"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:30088</id>
    <title>RHSA-2026:30088 — Red Hat Security Advisory: Red Hat AI Inference Server 3.3.5 (ROCm)</title>
    <updated>2026-10-02T22:34:16.301085+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication vLLM: vLLM: Remote code execution via invalid image processing in the multimodal endpoint. vLLM: vLLM: Arbitrary code execution via untrusted model loading pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID vLLM: vLLM: Server-Side Request Forgery allows internal network access OpenEXR: OpenEXR: Arbitrary code execution and information disclosure via crafted EXR file vim: arbitrary command execution via modeline sandbox bypass OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode sudo: Sudo: Privilege escalation due to failure in privilege drop calls libsndfile: integer overflow in ima_reader_init() cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers jq: jq: Denial of Service via crafted JSON object causing hash collisions urllib3: urllib3: Informati…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:30088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1974</id>
    <title>WID-SEC-W-2026-1974 — vllm: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-02T22:34:16.301146+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vllm ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1974"/>
  </entry>
</feed>
