216.73.217.22

CVE-2025-59425

· Published 07/10/2025 14:15 · Modified 08/10/2025 19:38

Labels: CVE-2025-59425 2025-10-07CVE-2025-59425CWE-385[email protected]

Essential information

Published
07/10/2025 14:15
Modified
08/10/2025 19:38
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS metrics

Description

vLLM is an inference and serving engine for large language models (LLMs). Before version 0.11.0rc2, the API key support in vLLM performs validation using a method that was vulnerable to a timing attack. API key validation uses a string comparison that takes longer the more characters the provided API key gets correct. Data analysis across many attempts could allow an attacker to determine when it finds the next correct character in the key sequence. Deployments relying on vLLM's built-in API key validation are vulnerable to authentication bypass using this technique. Version 0.11.0rc2 fixes the issue.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
vllm / vllm cpe:2.3:a:vllm:vllm:<0.11.0rc2:*:*:*:*:*:*:*

References