NEWS
Security Audit of vLLM
X41 performed a source code audit of vLLM, sponsored and organized by the Open Source Technology Improvement Fund.
vLLM originated at the University of California, Berkeley, and has grown into a widely deployed inference and serving engine for LLMs. It is largely written in Python and can be used with text or multimodal models and offers features such as tool calling and an OpenAI compatible API.
The source code in scope for this audit was v0.14.0, with a retest of the findings against v0.29.0.
Full report of the security audit: https://www.x41-dsec.de/static/reports/X41-OSTIF-vLLM-Audit-Public-Report-2026-10-06.pdf
Audit Results
Five vulnerabilities were discovered during the test by X41. One was rated as having a critical severity and four as high. Additionally, 15 issues without a direct security impact were identified.
The most severe issue was the discovery of the BadHost vulnerability (CVE-2026-48710), which allowed for an authentication bypass in vLLM and other projects. BadHost was found in dependencies of vLLM, and had a wider real-world impact. See our technical blog post for more information.
The remaining four vulnerabilities enabled different kinds of Denial of Service attacks via resource exhaustion, which would allow attackers to shut down the API without recovery.
For example, attackers could send a chat completion request with a large number of anyOf branches in the guided_json schema,
or request the loading of very large files via image_embeds, prompt_embeds, or multimodal media files.
The informational issues cover SSRF, information leaks, DoS, and hardening recommendations.
X41 also performed fuzzing tests against vLLM and its dependencies.
The full details can be found in the report.