Threat Advisory

vllm Flaw Lets Attackers Bypass SSRF Allowlist Policy

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in vLLM, affecting inference batching and multimodal processing. The advisory contains two Medium-severity vulnerabilities with CVSS v3 scores of 5.3 and 6.5. The flaws can result in cross-user inference data leakage, server-side request forgery (SSRF), and arbitrary local file disclosure.

CVE-2026-73558 (CVSS 5.3): A Medium-severity integer overflow vulnerability in the act_and_mul_kernel can cause inference results from one user's request to be incorrectly incorporated into another user's response within the same inference batch. Under specific batching and tensor-dimension conditions, an attacker can receive another user's complete or partial model output, resulting in cross-user sensitive information disclosure. The vulnerability affects vLLM versions prior to 0.27.0.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in vLLM, affecting inference batching and multimodal processing. The advisory contains two Medium-severity vulnerabilities with CVSS v3 scores of 5.3 and 6.5. The flaws can result in cross-user inference data leakage, server-side request forgery (SSRF), and arbitrary local file disclosure.

CVE-2026-73558 (CVSS 5.3): A Medium-severity integer overflow vulnerability in the act_and_mul_kernel can cause inference results from one user's request to be incorrectly incorporated into another user's response within the same inference batch. Under specific batching and tensor-dimension conditions, an attacker can receive another user's complete or partial model output, resulting in cross-user sensitive information disclosure. The vulnerability affects vLLM versions prior to 0.27.0.[emaillocker id="1283"]

CVE-2026-73560 (CVSS 6.5): A Medium-severity SSRF and arbitrary local file read vulnerability in the MiMoV2OmniMultiModalProcessor allows attacker-controlled image and audio URLs or local file paths to bypass vLLM's MediaConnector security protections. An attacker can potentially access internal services, cloud metadata endpoints, and files readable by the vLLM process. The vulnerable image and audio processing paths directly use network requests and local file operations without appropriate URL or path restrictions. The advisory lists vLLM versions prior to 0.26.0 as affected.

RECOMMENDATION:

We recommend you to update vllm to version 0.26.0.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu