PT-2026-57659 · Unknown · Vllm-Orchestrator-Gateway
CVE-2026-15574
·
Published
2026-07-13
·
Updated
2026-07-13
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
vllm-orchestrator-gateway (affected versions not specified)
Description
The vllm-orchestrator-gateway component logs all incoming authorization headers and full chat payloads to persistent logs. This includes sensitive data such as bearer tokens and chat content, which may contain personally identifiable information (PII) and secrets. Any user with logging privileges can access these logs, leading to information disclosure and the potential harvesting of credentials and sensitive conversation content.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vllm-Orchestrator-Gateway