CVE-2026-73555: vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in
Summary
vLLM, a software that runs and serves large language models, has a security flaw in versions before 0.26.0 where error messages from malformed requests reveal sensitive information like the operating system username, file paths, and internal code details to anyone who sends specially crafted requests. The problem occurs because the error handling code doesn't properly hide sensitive details when something goes wrong.
Solution / Mitigation
Update vLLM to version 0.26.0 or later. The source states: "This issue is fixed in version 0.26.0."
Vulnerability Details
5.3(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
network
low
none
none
August 13, 2026
Classification
Affected Vendors
Related Issues
GHSA-382c-vx95-w3p5: Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
CVE-2026-2589: The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73555
First tracked: August 13, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 95%