CVE-2025-59425: high-severity vulnerability in vllm-project vllm
vLLM vulnerable to timing attack at bearer auth
Published
No sign of exploitation. No public exploitation artifact known so far.
vLLM's API key validation is vulnerable to timing attacks, where an attacker can guess the correct API key character-by-character by measuring how long the server takes to reject each attempt. This allows attackers to bypass authentication and gain unauthorized access to the LLM service.
The API key validation in vLLM uses string comparison that exhibits timing variation based on the number of correct characters matched, enabling a timing side-channel attack. An attacker can iteratively determine each character of the API key by analyzing response times across multiple authentication attempts, leading to authentication bypass and unauthorized API access.
In the same product, most dangerous first.