vLLM: OpenAI auth bypass
GHSA-94f4-hr76-p5j6 · CVE-2026-48746 · PYSEC-2026-226
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Summary
A vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware, which was discovered during @x41sec's source code audit.
It allows to use the API without providing the configured VLLM_API_KEY or --api-key.
Details
In https://github.com/vllm-project/vllm/blob/v0.14.0/vllm/entrypoints/openai/api_server.py#L689-L692 the url_path is taken from the URL, which is reconstructed by starlette based on the request scope.
from starlette.datastructures import URL, Headers, MutableHeaders, State
# ...
url_path = URL(scope=scope).path.removeprefix(root_path)
headers = Headers(scope=scope)
if url_path.startswith("/v1") and not self.verify_token(headers):
response = JSONResponse(content={"error": "Unauthorized"}, status_code=401)
return response(scope, receive, send)
return self.app(scope, receive, send)
The request scope includes the request's Host: header and reconstructs the URL as shown below:
f"{scheme}://{host_header}{path}"
Neither starlette nor any of the ASGI servers (including uvicorn, which vllm uses) properly filter the Host: header for invalid characters. This allows an attacker to include special URL characters such as / or ? in the Host: header and thereby control the reconstructed URL and it's .path attribute.
FastAPI/starlette's routing uses the HTTP path and does not depend on the parsed url.path attribute, allowing attackers to reach an endpoint via a certain path while providing a different value in the .path.
Impact
- Instances of vllm that use an API Key for the OpenAI API and expose the API to attackers.
- Instances behind an RFC-conforming web server (such as nginx) are not affected.
References
- WEB https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-48746
- WEB https://github.com/vllm-project/vllm/pull/43426
- WEB https://x41-dsec.de/lab/advisories/x41-2026-002-starlette
- WEB https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48746.json
- PACKAGE https://github.com/vllm-project/vllm
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-226.yaml
- WEB https://bugzilla.redhat.com/show_bug.cgi?id=2491581
- WEB https://access.redhat.com/security/cve/CVE-2026-48746
- WEB https://access.redhat.com/errata/RHSA-2026:61629
- WEB https://access.redhat.com/errata/RHSA-2026:61627
- WEB https://access.redhat.com/errata/RHSA-2026:43038
- WEB https://access.redhat.com/errata/RHSA-2026:42644
- WEB https://access.redhat.com/errata/RHSA-2026:42142
- WEB https://access.redhat.com/errata/RHSA-2026:42132
- WEB https://access.redhat.com/errata/RHSA-2026:36006
- WEB https://access.redhat.com/errata/RHSA-2026:36005
- WEB https://access.redhat.com/errata/RHSA-2026:30089
- WEB https://access.redhat.com/errata/RHSA-2026:30088
Ready to move
Start Securing
Free, no credit card | First findings in minutes