Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
[Rust Frontend] Add /server_info to Rust frontend #43942
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Uh oh!
There was an error while loading. Please reload this page.
[Rust Frontend] Add /server_info to Rust frontend #43942
Changes from 1 commit
eb6af18bef6f083dfba11f4c2713e500725ffceba8e4844cdc522ee0a6dc5f010334b0File filter
Filter by extension
Conversations
Uh oh!
There was an error while loading. Please reload this page.
Jump to
Uh oh!
There was an error while loading. Please reload this page.
There are no files selected for viewing
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
What about also moving the construction-related logic into a separate module?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🟡 Severity: MEDIUM
Unlike the Python equivalent which iterates over a curated whitelist of ~240 known attributes in the
vllm.envsmodule, this function reads all OS environment variables matchingVLLM_*. Any custom deployment-set env var (e.g.VLLM_AUTH_TOKEN,VLLM_DB_PASSWORD) that doesn't contain "KEY" in its name would be leaked through the unauthenticated/server_infoendpoint.Helpful? Add 👍 / 👎
💡 Fix Suggestion
Suggestion: The
collect_vllm_env()function reads ALL OS environment variables matchingVLLM_*, unlike the Python equivalent which only iterates over a curated whitelist of ~240 known attributes defined invllm.envs. Any deployment-custom env var (e.g.VLLM_AUTH_TOKEN,VLLM_DB_PASSWORD) that doesn't contain "KEY" in its name would be leaked through the unauthenticated/server_infoendpoint.The ideal fix is to replicate the Python behavior by maintaining an explicit allowlist of known VLLM environment variable names (the ~240 variables defined in
vllm/envs.py), and only exposing those. This is a larger change requiring an allowlist constant to be kept in sync with the Pythonvllm.envsmodule.As an immediate improvement, enhance the denylist filter to exclude additional common sensitive patterns such as SECRET, TOKEN, PASSWORD, CREDENTIAL, and AUTH. This reduces the attack surface but is not as robust as the allowlist approach.
Uh oh!
There was an error while loading. Please reload this page.