Bug 2373716 (CVE-2025-6242) - CVE-2025-6242 vllm: Server Side request forgery (SSRF) in MediaConnector
Summary: CVE-2025-6242 vllm: Server Side request forgery (SSRF) in MediaConnector
Keywords:
Status: NEW
Alias: CVE-2025-6242
Deadline: 2025-10-07
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-06-18 15:28 UTC by OSIDB Bzimport
Modified: 2025-10-07 19:41 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-06-18 15:28:49 UTC
A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimodal feature set. The load_from_url and load_from_url_async methods fetch and process media from user-provided URLs without adequate restrictions on the target hosts. This allows an attacker to coerce the vLLM server into making arbitrary requests to internal network resources.


Note You need to log in before you can comment on or make changes to this bug.