PyPI: vllm

CVE-2026-54236

Safety vulnerability ID: SFTY-20260617-04058

Affected versions of the vLLM package are vulnerable to Information Disclosure due to inadequate sanitization of exception messages. The `api_router.py` and `connection.py` files contain exception handlers that directly echo `str(exc)` to clients without applying `sanitize_message`, allowing memory addresses to be included in error messages. An attacker can exploit this vulnerability by sending malformed image bytes that trigger exceptions, resulting in the leakage of heap addresses in the response body, significantly reducing ASLR entropy and potentially aiding in further attacks.

Created at: Jun 24, 2026Updated at: Jun 24, 2026

Overview

vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router

Advisory

vllm – Insertion of Sensitive Information into Log File

Affected Package

Affecting vllm package, versions
<= 0.23.0

Also affects

---

How to Fix

We recommend updating vllm to the latest non-vulnerable version.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more