PT-2026-60022 · Pypi · Vllm
Published
2026-07-13
·
Updated
2026-07-13
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L |
Summary
The SSRF protection fix for https://github.com/vllm-project/vllm/security/advisories/GHSA-qh4c-xf7m-gxfc can be bypassed in the
load from url async method due to inconsistent URL parsing behavior between the validation layer and the actual HTTP client.Affected Component
- File:
vllm/connections.py - Function:
load from url async
Vulnerability Details
Root Cause
The SSRF fix uses
urllib3.util.parse url() to validate and extract the hostname from user-provided URLs. However, load from url async uses aiohttp for making the actual HTTP requests, and aiohttp internally uses the yarl library for URL parsing.These two URL parsers handle backslash characters (``) differently:
| Parser | Input URL | Parsed Host | Parsed Path | Behavior |
|---|---|---|---|---|
urllib3.parse url() | https://httpbin.org@evil.com/ | httpbin.org | /%5C@evil.com/ | URL-encodes `` as %5C, treats @evil.com/ as part of the path |
yarl (via aiohttp) | https://httpbin.org@evil.com/ | evil.com | / | Treats `` as part of userinfo (user: httpbin.org), the @ acts as the userinfo/host separator |
Attack Scenario
python
# Attacker provides this URL
malicious url = "https://httpbin.org@evil.com/"
# 1. Validation layer (urllib3.parse url)
parsed = urllib3.util.parse url(malicious url)
# parsed.host == "httpbin.org" ✅ Passes validation
# 2. Actual request (aiohttp with yarl)
async with aiohttp.ClientSession() as session:
async with session.get(malicious url) as response:
# Request actually goes to evil.com! ❌ Bypass!Why This Happens
- yarl: Interprets
httpbin.orgas the userinfo component, and@as the userinfo/host separator, so the URL is parsed asuser=httpbin.org,host=evil.com,path=/ - urllib3: URL-encodes the backslash as
%5C, so@evil.com/becomes/%5C@evil.com/which is treated as part of the path, leavinghost=httpbin.org
This inconsistency allows an attacker to:
- Bypass the hostname allowlist check
- Access arbitrary internal/external services
- Perform full SSRF attacks
Fixes
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vllm