CVE advisoryCRITICAL
CVE-2026-25960
vLLM SSRF Protection Bypass Vulnerability
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A Server-Side Request Forgery (SSRF) vulnerability in vLLM, an LLM serving engine, can be bypassed due to inconsistent URL parsing, potentially allowing attackers to access internal network resources or execute arbitrary code.