<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:35:45 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-369283</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-369283</link>
      <description>EUVD-2026-369283</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-369283</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48746</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48746</link>
      <description>&lt;p&gt;vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette&amp;#39;s trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette&amp;#39;s trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48746</guid>
    </item>
    <item>
      <title>GHSA-94f4-hr76-p5j6 — vLLM: OpenAI auth bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-94f4-hr76-p5j6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vllm&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A vulnerability in ASGI web servers and starlette&amp;#39;s trust on those web servers enables an authentication bypass of the OpenAI API `AuthenticationMiddleware`, which was discovered during @x41sec&amp;#39;s source code audit.
It allows to use the API without providing the configured `VLLM_API_KEY` or `--api-key`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In https://github.com/vllm-project/vllm/blob/v0.14.0/vllm/entrypoints/openai/api_server.py#L689-L692 the `url_path` is taken from the `URL`, which is reconstructed by _starlette_ based on the request `scope`.&lt;/p&gt;
&lt;p&gt;```py
from starlette.datastructures import URL, Headers, MutableHeaders, State&lt;/p&gt;
&lt;p&gt;# ...&lt;/p&gt;
&lt;p&gt;url_path = URL(scope=scope).path.removeprefix(root_path)
headers = Headers(scope=scope)
if url_path.startswith(&amp;#34;/v1&amp;#34;) and not self.verify_token(headers):
    response = JSONResponse(content={&amp;#34;error&amp;#34;: &amp;#34;Unauthorized&amp;#34;}, status_code=401)
    return response(scope, receive, send)
return self.app(scope, receive, send)
```&lt;/p&gt;
&lt;p&gt;The request `scope` includes the request&amp;#39;s `Host:` header and reconstructs the URL as shown below:&lt;/p&gt;
&lt;p&gt;```py
f&amp;#34;{scheme}://{host_header}{path}&amp;#34;
```&lt;/p&gt;
&lt;p&gt;Neither starlette nor [any of the ASGI servers](https://asgi.readthedocs.io/en/latest/implementations.html#servers) (including uvicorn, which vllm uses) properly filter the `Host:` header for invalid characters. This allows an attacker to include special URL characters such as `/` or `?` in the `Host:` header and thereby control the reconstructed URL and it&amp;#39;s `.path` attribute.&lt;/p&gt;
&lt;p&gt;FastAPI/starlette&amp;#39;s routi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vllm&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A vulnerability in ASGI web servers and starlette&amp;#39;s trust on those web servers enables an authentication bypass of the OpenAI API `AuthenticationMiddleware`, which was discovered during @x41sec&amp;#39;s source code audit.
It allows to use the API without providing the configured `VLLM_API_KEY` or `--api-key`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In https://github.com/vllm-project/vllm/blob/v0.14.0/vllm/entrypoints/openai/api_server.py#L689-L692 the `url_path` is taken from the `URL`, which is reconstructed by _starlette_ based on the request `scope`.&lt;/p&gt;
&lt;p&gt;```py
from starlette.datastructures import URL, Headers, MutableHeaders, State&lt;/p&gt;
&lt;p&gt;# ...&lt;/p&gt;
&lt;p&gt;url_path = URL(scope=scope).path.removeprefix(root_path)
headers = Headers(scope=scope)
if url_path.startswith(&amp;#34;/v1&amp;#34;) and not self.verify_token(headers):
    response = JSONResponse(content={&amp;#34;error&amp;#34;: &amp;#34;Unauthorized&amp;#34;}, status_code=401)
    return response(scope, receive, send)
return self.app(scope, receive, send)
```&lt;/p&gt;
&lt;p&gt;The request `scope` includes the request&amp;#39;s `Host:` header and reconstructs the URL as shown below:&lt;/p&gt;
&lt;p&gt;```py
f&amp;#34;{scheme}://{host_header}{path}&amp;#34;
```&lt;/p&gt;
&lt;p&gt;Neither starlette nor [any of the ASGI servers](https://asgi.readthedocs.io/en/latest/implementations.html#servers) (including uvicorn, which vllm uses) properly filter the `Host:` header for invalid characters. This allows an attacker to include special URL characters such as `/` or `?` in the `Host:` header and thereby control the reconstructed URL and it&amp;#39;s `.path` attribute.&lt;/p&gt;
&lt;p&gt;FastAPI/starlette&amp;#39;s routi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-94f4-hr76-p5j6</guid>
    </item>
    <item>
      <title>PYSEC-2026-226</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-226</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vllm&lt;/p&gt;
&lt;p&gt;vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette&amp;#39;s trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vllm&lt;/p&gt;
&lt;p&gt;vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette&amp;#39;s trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-226</guid>
    </item>
    <item>
      <title>RHSA-2026:30088 — Red Hat Security Advisory: Red Hat AI Inference Server 3.3.5 (ROCm)</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:30088</link>
      <description>&lt;p&gt;libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication vLLM: vLLM: Remote code execution via invalid image processing in the multimodal endpoint. vLLM: vLLM: Arbitrary code execution via untrusted model loading pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID vLLM: vLLM: Server-Side Request Forgery allows internal network access OpenEXR: OpenEXR: Arbitrary code execution and information disclosure via crafted EXR file vim: arbitrary command execution via modeline sandbox bypass OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode sudo: Sudo: Privilege escalation due to failure in privilege drop calls libsndfile: integer overflow in ima_reader_init() cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers jq: jq: Denial of Service via crafted JSON object causing hash collisions urllib3: urllib3: Informati…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication vLLM: vLLM: Remote code execution via invalid image processing in the multimodal endpoint. vLLM: vLLM: Arbitrary code execution via untrusted model loading pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID vLLM: vLLM: Server-Side Request Forgery allows internal network access OpenEXR: OpenEXR: Arbitrary code execution and information disclosure via crafted EXR file vim: arbitrary command execution via modeline sandbox bypass OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode sudo: Sudo: Privilege escalation due to failure in privilege drop calls libsndfile: integer overflow in ima_reader_init() cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers jq: jq: Denial of Service via crafted JSON object causing hash collisions urllib3: urllib3: Informati…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:30088</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1974 — vllm: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1974</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vllm ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vllm ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1974</guid>
    </item>
  </channel>
</rss>
