SOURCE-LINKED INTELLIGENCE
GHSA-rxc4-3w6r-4v47: vllm API endpoints vulnerable to Denial of Service Attacks
### Summary A Denial of Service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large header to an HTTP endpoint. This results in server memory exhaustion, potentially leading to a crash or unresponsiveness. The attack does not require authentication, making it exploitable by any remote user. ### Details The vulnerability leverages the abuse of HTTP headers. By setting a header such as `X-Forwarded-For` to a very large value like `("A" * 5_800_000_000)`, the server's HTTP parser or application logic may attempt to load the entire request into memory,
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2025-08-21T14:24:16.000Z
- OSV AI package advisories · 2026-07-07T16:03:01.559Z
First collected: 2026-09-20T22:31:48.298Z. This is not the publication date.