CVE-2026-73555
vLLM information disclosure from improper error handling in API endpoints.
- CVSS 5.3
- 209
- Information Leakage
- Remote
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_message in vllm/entrypoints/utils.py does not remove traceback-style file paths, allowing unauthenticated malformed JSON requests to /v1/chat/completions, /v1/completions, /tokenize, and /detokenize to disclose the OS username, home and virtual-environment paths, Python version, internal package structure, line numbers, and endpoint handler names. This issue is fixed in version 0.26.0.
- CWE
- 209
- CVSS base score
- 5.3
- Published
- 2026-08-13
- OWASP
- A05 Security Misconfiguration
- Orthogonal defect classification
- Checking
- Code defect classification
- Incorrect Check
- Category
- Information Leakage
- Subcategory
- Information Disclosure
- Accessibility scope
- Remote
- Impact
- Information Disclosure
- Affected component
- vLLM
- Fixed by upgrading
- Yes
Solution
Upgrade vLLM to version 0.26.0 or later.
Vulnerable code sample
from fastapi import Request
from fastapi.exceptions import RequestValidationError
from fastapi.responses import JSONResponse
# Dummy implementation for context: in the real library, this function
# failed to remove traceback paths from the error message.
def sanitize_message(message: str) -> str:
return message
# Dummy implementation for context.
def create_error_response(message: str) -> JSONResponse:
return JSONResponse(
content={"error": {"message": message}},
status_code=400
)
async def validation_exception_handler(
_request: Request, exc: RequestValidationError
) -> JSONResponse:
# VULNERABLE: str(exc) on a RequestValidationError includes a traceback with sensitive file paths.
return create_error_response(message=sanitize_message(str(exc)))Patched code sample
from fastapi import Request
from fastapi.exceptions import RequestValidationError
from fastapi.responses import JSONResponse
# Dummy implementation for context.
def create_error_response(message: str) -> JSONResponse:
return JSONResponse(
content={"error": {"message": message}},
status_code=400
)
async def validation_exception_handler(
_request: Request, exc: RequestValidationError
) -> JSONResponse:
err_msg = ""
# FIX: Manually construct a safe error message from structured validation details, avoiding the traceback.
for pydantic_err in exc.errors():
err_msg += (
f"Validation error in '{'.'.join(map(str, pydantic_err['loc']))}': "
f"{pydantic_err['msg']} ({pydantic_err['type']}). "
)
return create_error_response(message=err_msg.strip())Payload
{
"model": "x",
"messages": "x",
"temperature": "not-a-float"
}
Cite this entry
@misc{vaitp:cve202673555,
title = {{vLLM information disclosure from improper error handling in API endpoints.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2026},
note = {VAITP Python Vulnerability Dataset, entry CVE-2026-73555},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-73555/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
