{"id":"GHSA-94f4-hr76-p5j6","summary":"vLLM: OpenAI auth bypass","details":"### Summary\n\nA vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API `AuthenticationMiddleware`, which was discovered during @x41sec's source code audit.\nIt allows to use the API without providing the configured `VLLM_API_KEY` or `--api-key`.\n\n### Details\n\nIn https://github.com/vllm-project/vllm/blob/v0.14.0/vllm/entrypoints/openai/api_server.py#L689-L692 the `url_path` is taken from the `URL`, which is reconstructed by _starlette_ based on the request `scope`.\n\n```py\nfrom starlette.datastructures import URL, Headers, MutableHeaders, State\n\n# ...\n\nurl_path = URL(scope=scope).path.removeprefix(root_path)\nheaders = Headers(scope=scope)\nif url_path.startswith(\"/v1\") and not self.verify_token(headers):\n    response = JSONResponse(content={\"error\": \"Unauthorized\"}, status_code=401)\n    return response(scope, receive, send)\nreturn self.app(scope, receive, send)\n```\n\nThe request `scope` includes the request's `Host:` header and reconstructs the URL as shown below:\n\n```py\nf\"{scheme}://{host_header}{path}\"\n```\n\nNeither starlette nor [any of the ASGI servers](https://asgi.readthedocs.io/en/latest/implementations.html#servers) (including uvicorn, which vllm uses) properly filter the `Host:` header for invalid characters. This allows an attacker to include special URL characters such as `/` or `?` in the `Host:` header and thereby control the reconstructed URL and it's `.path` attribute.\n\nFastAPI/starlette's routing uses the HTTP path and does not depend on the parsed url.path attribute, allowing attackers to reach an endpoint via a certain path while providing a different value in the `.path`.\n\n### Impact\n- Instances of vllm that use an API Key for the OpenAI API and expose the API to attackers.\n- Instances behind an RFC-conforming web server (such as nginx) are **not** affected.","aliases":["CVE-2026-48746","PYSEC-2026-226"],"modified":"2026-09-10T03:50:49.016998148Z","published":"2026-06-16T17:36:41Z","database_specific":{"nvd_published_at":"2026-06-22T23:16:30Z","cwe_ids":["CWE-444","CWE-501"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-06-16T17:36:41Z"},"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48746"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/43426"},{"type":"WEB","url":"https://x41-dsec.de/lab/advisories/x41-2026-002-starlette"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48746.json"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-226.yaml"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491581"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-48746"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:61629"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:61627"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:43038"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:42644"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:42142"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:42132"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:36006"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:36005"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:30089"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:30088"}],"affected":[{"package":{"name":"vllm","ecosystem":"PyPI","purl":"pkg:pypi/vllm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.3.0"},{"fixed":"0.22.0"}]}],"versions":["0.10.0","0.10.1","0.10.1.1","0.10.2","0.11.0","0.11.1","0.11.2","0.12.0","0.13.0","0.14.0","0.14.1","0.15.0","0.15.1","0.16.0","0.17.0","0.17.1","0.18.0","0.18.1","0.19.0","0.19.1","0.20.0","0.20.1","0.20.2","0.21.0","0.3.0","0.3.1","0.3.2","0.3.3","0.4.0","0.4.0.post1","0.4.1","0.4.2","0.4.3","0.5.0","0.5.0.post1","0.5.1","0.5.2","0.5.3","0.5.3.post1","0.5.4","0.5.5","0.6.0","0.6.1","0.6.1.post1","0.6.1.post2","0.6.2","0.6.3","0.6.3.post1","0.6.4","0.6.4.post1","0.6.5","0.6.6","0.6.6.post1","0.7.0","0.7.1","0.7.2","0.7.3","0.8.0","0.8.1","0.8.2","0.8.3","0.8.4","0.8.5","0.8.5.post1","0.9.0","0.9.0.1","0.9.1","0.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-94f4-hr76-p5j6/GHSA-94f4-hr76-p5j6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}