{"data":{"id":"0c0fb401-a84a-41b0-9ab6-72fad19b95b3","title":"CVE-2026-73555: vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in ","summary":"vLLM, a software that runs and serves large language models, has a security flaw in versions before 0.26.0 where error messages from malformed requests reveal sensitive information like the operating system username, file paths, and internal code details to anyone who sends specially crafted requests. The problem occurs because the error handling code doesn't properly hide sensitive details when something goes wrong.","solution":"Update vLLM to version 0.26.0 or later. The source states: \"This issue is fixed in version 0.26.0.\"","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73555","publishedAt":"2026-08-13T15:20:17.773Z","cveId":"CVE-2026-73555","cweIds":["CWE-209"],"cvssScore":"5.3","cvssSeverity":"medium","severity":"medium","attackType":["pii_leakage"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LlamaIndex"],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-13T15:20:17.773Z","capecIds":["CAPEC-54"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}