CVE-2026-34753 | vllm-project vLLM up to 0.18.x URL Validation download_bytes_from_url server-side request forgery (GHSA-pf3h-qjgv-vcpr)
A vulnerability, which was classified as critical, has been found in vllm-project vLLM up to 0.18.x. This impacts the function download_bytes_from_url of the component URL Validation Handler. This manipulation causes server-side request forgery.
This vulnerability appears as CVE-2026-34753. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.