What is CVE-2026-71486?
A security vulnerability in vLLM's /v1/completions/derender endpoint allows unauthenticated manipulation of GenerateResponse objects, potentially leading to information disclosure. Users must update to vLLM version 0.26.0 or later immediately.
Azərbaycanca: vLLM-in /v1/completions/derender endpointində təhlükəsizlik zəifliyi aşkar edilib. Bu, təsdiq olunmamış istifadəçilərə GenerateResponse obyektlərini manipulyasiya etməyə imkan verir, nəticədə məxfilik pozulmasına səbəb ola bilər. vLLM istifadəçiləri dərhal 0.26.0 versiyasına yeniləmə etməlidir.
FAQ2
What kind of vulnerability has been discovered in vLLM's /v1/completions/derender endpoint?
A security vulnerability has been discovered in vLLM's /v1/completions/derender endpoint that allows unauthenticated manipulation of GenerateResponse objects, potentially leading to information disclosure.
To which version should vLLM users update to protect against this vulnerability?
vLLM users should update to version 0.26.0 or later immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.