<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:09:53 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-73555 — vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-73555</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vllm-project vllm&lt;/p&gt;
&lt;p&gt;vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_message in vllm/entrypoints/utils.py does not remove traceback-style file paths, allowing unauthenticated malformed JSON requests to /v1/chat/completions, /v1/completions, /tokenize, and /detokenize to disclose the OS username, home and virtual-environment paths, Python version, internal package structure, line numbers, and endpoint handler names. This issue is fixed in version 0.26.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vllm-project vllm&lt;/p&gt;
&lt;p&gt;vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_message in vllm/entrypoints/utils.py does not remove traceback-style file paths, allowing unauthenticated malformed JSON requests to /v1/chat/completions, /v1/completions, /tokenize, and /detokenize to disclose the OS username, home and virtual-environment paths, Python version, internal package structure, line numbers, and endpoint handler names. This issue is fixed in version 0.26.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-73555</guid>
    </item>
    <item>
      <title>GHSA-hwrm-c4cx-rf4j — vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hwrm-c4cx-rf4j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vllm&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When the vLLM API receives a malformed request (e.g., invalid JSON or missing required fields), FastAPI raises a Pydantic `RequestValidationError`. The `validation_exception_handler` in `vllm/entrypoints/openai/server_utils.py` converts this exception to a string via `str(exc)`, which includes the internal file path and line number of the handler function. The existing `sanitize_message()` function in `vllm/entrypoints/utils.py` strips memory addresses (e.g., `0x7f...`) but does not strip `File &amp;#34;...&amp;#34;, line X` patterns. The result is a user-facing HTTP response that leaks internal system information.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An unauthenticated attacker can extract the following with a single malformed request:&lt;/p&gt;
&lt;p&gt;- **OS username** running the vLLM process (e.g., `ubuntu`)
- **Home directory path** (e.g., `/home/ubuntu/`)
- **Virtual environment path** (e.g., `vllm-env/`)
- **Python version** (e.g., `3.12`)
- **Internal package structure and line numbers** (e.g., `vllm/entrypoints/openai/chat_completion/api_router.py`)
- **Handler function names per endpoint**, enabling precise version fingerprinting&lt;/p&gt;
&lt;p&gt;This information aids attackers in constructing targeted exploits: environment paths narrow the attack surface, and handler function names + line numbers enable exact version identification even when the `/version` endpoint is disabled.&lt;/p&gt;
&lt;p&gt;All POST endpoints that accept JSON bodies are affected, including `/v1/chat/completions`, `/v1/completions`, `/tokenize`, and `/detokenize`.&lt;/p&gt;
&lt;p&gt;## W…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vllm&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When the vLLM API receives a malformed request (e.g., invalid JSON or missing required fields), FastAPI raises a Pydantic `RequestValidationError`. The `validation_exception_handler` in `vllm/entrypoints/openai/server_utils.py` converts this exception to a string via `str(exc)`, which includes the internal file path and line number of the handler function. The existing `sanitize_message()` function in `vllm/entrypoints/utils.py` strips memory addresses (e.g., `0x7f...`) but does not strip `File &amp;#34;...&amp;#34;, line X` patterns. The result is a user-facing HTTP response that leaks internal system information.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An unauthenticated attacker can extract the following with a single malformed request:&lt;/p&gt;
&lt;p&gt;- **OS username** running the vLLM process (e.g., `ubuntu`)
- **Home directory path** (e.g., `/home/ubuntu/`)
- **Virtual environment path** (e.g., `vllm-env/`)
- **Python version** (e.g., `3.12`)
- **Internal package structure and line numbers** (e.g., `vllm/entrypoints/openai/chat_completion/api_router.py`)
- **Handler function names per endpoint**, enabling precise version fingerprinting&lt;/p&gt;
&lt;p&gt;This information aids attackers in constructing targeted exploits: environment paths narrow the attack surface, and handler function names + line numbers enable exact version identification even when the `/version` endpoint is disabled.&lt;/p&gt;
&lt;p&gt;All POST endpoints that accept JSON bodies are affected, including `/v1/chat/completions`, `/v1/completions`, `/tokenize`, and `/detokenize`.&lt;/p&gt;
&lt;p&gt;## W…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hwrm-c4cx-rf4j</guid>
    </item>
  </channel>
</rss>
