PT-2026-57659 · Unknown · Vllm-Orchestrator-Gateway

CVE-2026-15574

·

Published

2026-07-13

·

Updated

2026-07-13

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions vllm-orchestrator-gateway (affected versions not specified)
Description The vllm-orchestrator-gateway component logs all incoming authorization headers and full chat payloads to persistent logs. This includes sensitive data such as bearer tokens and chat content, which may contain personally identifiable information (PII) and secrets. Any user with logging privileges can access these logs, leading to information disclosure and the potential harvesting of credentials and sensitive conversation content.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15574

Affected Products

Vllm-Orchestrator-Gateway