SOURCE-LINKED INTELLIGENCE
GHSA-hwrm-c4cx-rf4j: vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
## Summary When the vLLM API receives a malformed request (e.g., invalid JSON or missing required fields), FastAPI raises a Pydantic `RequestValidationError`. The `validation_exception_handler` in `vllm/entrypoints/openai/server_utils.py` converts this exception to a string via `str(exc)`, which includes the internal file path and line number of the handler function. The existing `sanitize_message()` function in `vllm/entrypoints/utils.py` strips memory addresses (e.g., `0x7f...`) but does not strip `File "...", line X` patterns. The result is a user-facing HTTP response that leaks internal sy
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2026-09-04T21:36:33.000Z
- OSV AI package advisories · 2026-09-10T09:45:00.131Z
First collected: 2026-09-20T22:31:48.298Z. This is not the publication date.