CVE-2026-25960
The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in the load_from_url_async method due to inconsistent URL parsing behavior between the validation layer and the actual HTTP client.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in the load_from_url_async method due to inconsistent URL parsing behavior between the validation layer and the actual HTTP client. The SSRF fix uses urllib3.util.parse_url() to validate and extract the hostname from user-provided URLs. However, load_from_url_async uses aiohttp for making the actual HTTP requests, and aiohttp internally uses the yarl library for URL parsing. This vulnerability in 0.17.0.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918, CWE-474
- Affected
- vllm/vllm
- Source
- security-advisories@github.com
References
- https://github.com/vllm-project/vllm/commit/6f3b2047abd4a748e3db4a68543f8221358002c0Patch
- https://github.com/vllm-project/vllm/pull/34743Issue Tracking, Patch
- https://github.com/vllm-project/vllm/security/advisories/GHSA-qh4c-xf7m-gxfcNot Applicable
- https://github.com/vllm-project/vllm/security/advisories/GHSA-v359-jj2v-j536Exploit, Patch, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:24977
- https://access.redhat.com/errata/RHSA-2026:42644
- https://access.redhat.com/security/cve/CVE-2026-25960
- https://bugzilla.redhat.com/show_bug.cgi?id=2445892
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25960.json
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.