THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hwrm-c4cx-rf4j (medium) — vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

[GHSA] GHSA-hwrm-c4cx-rf4j (medium) — vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

medgithub_advisoriesPublished 2026-09-04

GHSA-hwrm-c4cx-rf4j Severity: medium CVE: CVE-2026-73555

vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

## Summary

When the vLLM API receives a malformed request (e.g., invalid JSON or missing required fields), FastAPI raises a Pydantic `RequestValidationError`. The `validation_exception_handler` in `vllm/entrypoints/openai/server_utils.py` converts th

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hwrm-c4cx-rf4j