← advisory ledger

ADVISORY UNAUTH-2026-0040
TYPE cve
PRODUCT vLLM
SEVERITY MEDIUM

MEDIUM

vLLM CVE-2026-54236

published 2026-08-05 · updated 2026-08-05

Why it matters

Incomplete fix for CVE-2026-22778: error responses from the Anthropic-compatible router and speech-to-text realtime endpoint leak Python object representations containing process memory addresses (CWE-532), useful for bypassing ASLR in follow-on exploitation.

Affected versions

  • <=0.23.0

Fixed in: 0.24.0

Mapping provenance: human-verified against the linked advisory, last checked 2026-07-29.

Fix it

Fix card: cve-2026-54236 →

References

Cite this record

unauth.dev advisory UNAUTH-2026-0040 — published 2026-08 · CC-BY 4.0

Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0040. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.