A critical vulnerability (CVSS Base Score 9.1) in the vLLM library allows a remote, anonymous attacker to bypass security controls. The flaw affects vLLM versions prior to 0.22.0, and a mitigation is available.
[WID-SEC-2026-1974] vllm: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen CVSS Base Score 9.1 (kritisch) CVSS Temporal Score 7.9 (hoch) Remoteangriff ja Datum 16.06.2026 Stand 17.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux UNIX Produktbeschreibung Open Source vLLM ist eine Open-Source-Bibliothek für schnelle und effiziente Inferenz von Large Language Models (LLMs). Produkte 16.06.2026 Open Source vllm <0.22.0 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vllm ausnutzen, um Sicherheitsvorkehrungen zu umgehen. CVE Informationen Versionshistorie Feedback zum Advisory geben