Database/AI/ML frameworks & serving
vLLM (`MediaConnector` SSRF): SSRF via `load_from_url` in multimodal input handling
CVSS 7.1CVE-2025-6242AI/ML frameworks & servingcurated
Impact
SSRF via load_from_url in multimodal input handling
Who can reach it
Unauthenticated request supplying an image URL — reaches cloud metadata endpoints and internal control planes
What to do
Upgrade and block link-local metadata (169.254.169.254) at the pod network layer. Provider-owned: IMDS reachability from tenant pods is an infrastructure decision
References
Related entries
- vLLM (`Nemotron_Nano_VL_Config`): RCE via a config class evaluated at model loadCVE-2025-66448 · vLLM (`Nemotron_Nano_VL_Config`)High
- vLLM: remote media is fully materialized before size and per-prompt limits are enforcedCVE-2026-100650 · vLLM (media acquisition layer, audio_url/base64 chat path, batch speech runner, Rust frontend /tokenize)High
- vLLM: overlong token_ids on the disaggregated serving endpoint crash the workerCVE-2026-100651 · vLLM (disaggregated serving endpoint /inference/v1/generate, decoder prompt-length validation)High
- vLLM: out-of-range stop_token_ids trigger a CUDA device assertion and wedge EngineCoreCVE-2026-100654 · vLLM (OpenAI-compatible /v1/completions and /v1/chat/completions, stop_token_ids validation)High
- vLLM (`MediaConnector`): SSRF, recurrence of CVE-2025-6242CVE-2026-24779 · vLLM (`MediaConnector`)High
- vLLM (`load_from_url_async`): Bypass of the CVE-2026-24779 SSRF fixCVE-2026-25960 · vLLM (`load_from_url_async`)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.