CVE-2026-34753 is a server-side request forgery vulnerability in vLLM, an inference and serving engine for large language models. In versions 0.16.0 through before 0.19.0, the batch runner function download_bytes_from_url accepts attacker-controlled URL values from batch input JSON and issues outbound HTTP or HTTPS requests without URL validation or domain restrictions. This allows untrusted input to influence server-side network requests and enables access attempts to resources reachable from the vLLM host, including internal HTTP APIs and cloud metadata services.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Docker lab demonstrating an SSRF vulnerability labeled CVE-2026-34753 against vLLM-like batch processing behavior. The structure is split into two services: an attacker container and a victim container, orchestrated by docker-compose. The victim service runs two Python aiohttp applications: victim/app.py exposes a POST /v1/batch API on port 8000 and contains the vulnerable logic, while victim/metadata.py runs a localhost-only mock cloud metadata service on 127.0.0.1:8080 that returns fake AWS-style IAM credentials. The vulnerable function download_bytes_from_url() accepts attacker-controlled URLs with schemes data, http, and https, and performs session.get(url) for http/https with no allowlist, host filtering, or loopback/internal address protection. The batch handler extracts body.file_url from JSON input and fetches it, then returns a preview of the fetched bytes, making SSRF directly observable and useful for exfiltration. The attacker side contains a simple shell script, attacker/attack.sh, and a JSON payload file, attacker/exploit.jsonl. The script probes the victim endpoint at http://victim:8000/v1/batch and then sends a POST request with the payload from exploit.jsonl. That payload sets file_url to http://127.0.0.1:8080/latest/meta-data/iam/security-credentials/admin-role, causing the victim to request its own localhost-only metadata service. Because the metadata service is not exposed externally and binds only to 127.0.0.1, successful retrieval proves SSRF into an internal-only endpoint. The response body includes a preview of the fetched secret data, including simulated AccessKeyId, SecretAccessKey, token, and expiration fields. Overall, this is a real exploit lab rather than a detector. It demonstrates web/network SSRF against a batch API, targeting internal services reachable from the vulnerable server. The exploit is operational but basic: the payload is hardcoded and intended to show credential theft from a cloud-metadata-like endpoint.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.