Skip to content

Known CVE

vLLM <= 0.23.0 - Anthropic Router Heap Address Information Leak

vLLM <= 0.23.0 incompletely fixes CVE-2026-22778. The original fix added sanitize_message to the OpenAI router but the Anthropic-compatible router (/v1/messages) echoes str(exc) directly.

CVE-2026-54236

Medium2026CVSS 5.3CWE-532

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website