CVE-2026-25960 | vLLM up to 0.16.x Incomplete Fix CVE-2026-24779 urllib3.util.parse_url server-side request forgery (GHSA-qh4c-xf7m-gxfc)
A vulnerability, which was classified as critical, has been found in vLLM up to 0.16.x. This impacts the function urllib3.util.parse_url of the component Incomplete Fix CVE-2026-24779. Performing a manipulation results in server-side request forgery.
This vulnerability is known as CVE-2026-25960. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.