vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
PYSEC-2026-3937 · CVE-2026-73555 · GHSA-hwrm-c4cx-rf4j
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Summary
When the vLLM API receives a malformed request (e.g., invalid JSON or missing required fields), FastAPI raises a Pydantic RequestValidationError. The validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts this exception to a string via str(exc), which includes the internal file path and line number of the handler function. The existing sanitize_message() function in vllm/entrypoints/utils.py strips memory addresses (e.g., 0x7f...) but does not strip File "...", line X patterns. The result is a user-facing HTTP response that leaks internal system information.
Impact
An unauthenticated attacker can extract the following with a single malformed request:
- OS username running the vLLM process (e.g.,
ubuntu) - Home directory path (e.g.,
/home/ubuntu/) - Virtual environment path (e.g.,
vllm-env/) - Python version (e.g.,
3.12) - Internal package structure and line numbers (e.g.,
vllm/entrypoints/openai/chat_completion/api_router.py) - Handler function names per endpoint, enabling precise version fingerprinting
This information aids attackers in constructing targeted exploits: environment paths narrow the attack surface, and handler function names + line numbers enable exact version identification even when the /version endpoint is disabled.
All POST endpoints that accept JSON bodies are affected, including /v1/chat/completions, /v1/completions, /tokenize, and /detokenize.
Workarounds
Deploying vLLM behind a reverse proxy that rewrites error response bodies to strip file paths would mitigate this, though it is fragile.
Remediation Recommendation
Two possible fixes (either suffices):
Option A — Fix validation_exception_handler: Construct the error message from exc.errors() (the structured Pydantic error list) rather than str(exc). This avoids the traceback-style string entirely.
Option B — Fix sanitize_message: Add a regex to strip File "...", line \d+ patterns, similar to how memory addresses are already stripped:
import re
msg = re.sub(r'File ".*?", line \d+, in \w+', '[internal]', msg)
Option A is preferred as it addresses the root cause rather than filtering symptoms.
Environment Tested
- vLLM 0.20.1 (pip install, latest stable as of May 2026)
- Python 3.12
- Ubuntu 22.04
- Model: Qwen/Qwen2-0.5B (text-only; bug is model-independent)
This was fixed here: https://github.com/vllm-project/vllm/commit/e87521626f
References
- WEB https://github.com/vllm-project/vllm/security/advisories/GHSA-hwrm-c4cx-rf4j
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-73555
- WEB https://github.com/vllm-project/vllm/pull/46415
- WEB https://github.com/vllm-project/vllm/commit/e87521626febe2763f997691d1599de4175f4324
- PACKAGE https://github.com/vllm-project/vllm
- WEB https://github.com/vllm-project/vllm/releases/tag/v0.26.0
- PACKAGE https://pypi.org/project/vllm
- ADVISORY https://github.com/advisories/GHSA-hwrm-c4cx-rf4j
Ready to move
Start Securing
Free, no credit card | First findings in minutes