PT-2026-60022 · Pypi · Vllm

Published

2026-07-13

·

Updated

2026-07-13

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

Summary

The SSRF protection fix for https://github.com/vllm-project/vllm/security/advisories/GHSA-qh4c-xf7m-gxfc can be bypassed in the load from url async method due to inconsistent URL parsing behavior between the validation layer and the actual HTTP client.

Affected Component

  • File: vllm/connections.py
  • Function: load from url async

Vulnerability Details

Root Cause

The SSRF fix uses urllib3.util.parse url() to validate and extract the hostname from user-provided URLs. However, load from url async uses aiohttp for making the actual HTTP requests, and aiohttp internally uses the yarl library for URL parsing.
These two URL parsers handle backslash characters (``) differently:
ParserInput URLParsed HostParsed PathBehavior
urllib3.parse url()https://httpbin.org@evil.com/httpbin.org/%5C@evil.com/URL-encodes `` as %5C, treats @evil.com/ as part of the path
yarl (via aiohttp)https://httpbin.org@evil.com/evil.com/Treats `` as part of userinfo (user: httpbin.org), the @ acts as the userinfo/host separator

Attack Scenario

python
# Attacker provides this URL
malicious url = "https://httpbin.org@evil.com/"

# 1. Validation layer (urllib3.parse url)
parsed = urllib3.util.parse url(malicious url)
# parsed.host == "httpbin.org" ✅ Passes validation

# 2. Actual request (aiohttp with yarl)
async with aiohttp.ClientSession() as session:
  async with session.get(malicious url) as response:
    # Request actually goes to evil.com! ❌ Bypass!

Why This Happens

  1. yarl: Interprets httpbin.org as the userinfo component, and @ as the userinfo/host separator, so the URL is parsed as user=httpbin.org, host=evil.com, path=/
  2. urllib3: URL-encodes the backslash as %5C, so @evil.com/ becomes /%5C@evil.com/ which is treated as part of the path, leaving host=httpbin.org
This inconsistency allows an attacker to:
  • Bypass the hostname allowlist check
  • Access arbitrary internal/external services
  • Perform full SSRF attacks

Fixes

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-3411

Affected Products

Vllm