Known CVE
vLLM <= 0.23.0 - Anthropic Router Heap Address Information Leak
vLLM <= 0.23.0 incompletely fixes CVE-2026-22778. The original fix added sanitize_message to the OpenAI router but the Anthropic-compatible router (/v1/messages) echoes str(exc) directly.
CVE-2026-54236
Medium2026CVSS 5.3CWE-532
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website