REDHAT-BUG-2491581: High severity vllm vulnerability
vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLMAPIKEY or --api-key. This vulnerability is fixed in 0.22.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vLLMto a version that resolves this vulnerability.Fixed in 0.22.0
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2491581?
The severity of REDHAT-BUG-2491581 is high, rated at 7.
How do I fix REDHAT-BUG-2491581?
To fix REDHAT-BUG-2491581, update vLLM to a version above 0.22.0.
What consequences does REDHAT-BUG-2491581 pose?
REDHAT-BUG-2491581 allows an authentication bypass for the OpenAI API, enabling unauthorized usage.
Which versions of vLLM are affected by REDHAT-BUG-2491581?
Versions of vLLM from 0.3.0 until 0.22.0 are affected by REDHAT-BUG-2491581.
What is vLLM in relation to REDHAT-BUG-2491581?
vLLM is an inference and serving engine for large language models that is impacted by REDHAT-BUG-2491581.