CVE-2025-59425: vLLM vulnerable to timing attack at bearer auth

Published Oct 7, 2025
·
Updated

Summary The API key support in vLLM performed validation using a method that was vulnerable to a timing attack. This could potentially allow an attacker to discover a valid API key using an approach more efficient than brute force.

Details https://github.com/vllm-project/vllm/blob/4b946d693e0af15740e9ca9c0e059d5f333b1083/vllm/entrypoints/openai/apiserver.py#L1270-L1274

API key validation used a string comparison that will take longer the more characters the provided API key gets correct. Data analysis across many attempts can allow an attacker to determine when it finds the next correct character in the key sequence. Impact Deployments relying on vLLM's built-in API key validation are vulnerable to authentication bypass using this technique.

Other sources

vLLM is an inference and serving engine for large language models (LLMs). Before version 0.11.0rc2, the API key support in vLLM performs validation using a method that was vulnerable to a timing attack. API key validation uses a string comparison that takes longer the more characters the provided API key gets correct. Data analysis across many attempts could allow an attacker to determine when it finds the next correct character in the key sequence. Deployments relying on vLLM's built-in API key validation are vulnerable to authentication bypass using this technique. Version 0.11.0rc2 fixes the issue.

MITRE

Affected Software

4 affected componentsFixes available
vllm vllm<0.11.0rc2
pip/vllm<0.11.0
0.11.0
vllm vllm<0.11.0
vllm vllm=0.11.0-rc1

Event History

Oct 7, 2025
CVE Published
via MITRE·02:06 PM
Data Sourced
via MITRE·02:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·05:24 PM
Data Sourced
via GitHub·05:24 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-59425?

CVE-2025-59425 is considered a medium severity vulnerability due to its potential for timing attacks on API key validation.

2

How do I fix CVE-2025-59425?

To fix CVE-2025-59425, update vLLM to version 0.11.0rc2 or later where the API key validation issue has been addressed.

3

What is the impact of CVE-2025-59425 on my application?

The impact of CVE-2025-59425 could allow attackers to exploit the timing attack to potentially bypass API key security mechanisms.

4

Is CVE-2025-59425 present in my version of vLLM?

CVE-2025-59425 affects vLLM versions prior to 0.11.0rc2, so any versions below this are vulnerable.

5

What type of vulnerability is CVE-2025-59425 classified as?

CVE-2025-59425 is classified as a timing attack vulnerability related to API key validation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203