THREAT OPS › Threat News › [GHSA] GHSA-hwrm-c4cx-rf4j (medium) — vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
[GHSA] GHSA-hwrm-c4cx-rf4j (medium) — vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
GHSA-hwrm-c4cx-rf4j Severity: medium CVE: CVE-2026-73555
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
## Summary
When the vLLM API receives a malformed request (e.g., invalid JSON or missing required fields), FastAPI raises a Pydantic `RequestValidationError`. The `validation_exception_handler` in `vllm/entrypoints/openai/server_utils.py` converts th
Indicators of compromise
- CVE-2026-73555cve
Original source: https://github.com/advisories/GHSA-hwrm-c4cx-rf4j