Executive brief
vLLM is an engine used to serve Large Language Models (LLMs) via an API. A security flaw allows attackers to bypass the required API key authentication by sending specially crafted web requests. This could allow unauthorized users to access and use expensive AI resources or sensitive model endpoints without permission.
Technical details
An authentication bypass exists in vLLM's OpenAI API server due to inconsistent interpretation of HTTP requests. The `AuthenticationMiddleware` reconstructs the request URL using the `Host` header provided by the ASGI server (such as uvicorn). Because these servers do not strictly validate the `Host` header, an attacker can inject special characters (like `/` or `?`) into the header to manipulate the reconstructed `url.path` used for security checks. While the middleware sees a path that appears to bypass authentication requirements, the underlying Starlette router still directs the request to the intended protected endpoint. This allows remote, unauthenticated attackers to access the API without a valid `VLLM_API_KEY`. The issue is mitigated if vLLM is deployed behind an RFC-conforming reverse proxy like Nginx.
Affected products
- vllm-project vLLM >= 0.3.0, < 0.22.0
Timeline
- 2026-01-27: other: Issue identified during source code audit
- 2026-05-22: other: Pull request submitted to fix path extraction
- 2026-06-22: advisory: NVD and GitHub advisories published