{"data":{"ecosystem":"pypi","name":"vllm","url":"https://aisecwatch.com/packages/pypi/vllm","latestVersion":"0.31.0","firstReleaseAt":"2023-06-19T08:21:42.236Z","repository":"https://github.com/vllm-project/vllm","llm":{"exposure":"direct","depth":0,"integratedAt":"2023-08-25T04:12:50.248Z","integratedVersion":"0.1.4","sdks":["anthropic","huggingface","mcp","openai","outlines"],"path":[]},"authority":{"profile":["http","mcp_tools"],"fromDependencies":["pypi:aiohttp","pypi:mcp","pypi:requests"]},"dependencies":[{"ecosystem":"pypi","name":"anthropic","versionSpec":">=0.71.0","scope":"runtime"},{"ecosystem":"pypi","name":"b12x","versionSpec":"==1.3.0","scope":"extra:b12x"},{"ecosystem":"pypi","name":"compressed-tensors","versionSpec":"==0.17.0","scope":"runtime"},{"ecosystem":"pypi","name":"datasets","versionSpec":null,"scope":"extra:bench"},{"ecosystem":"pypi","name":"fastsafetensors","versionSpec":">=0.3.3","scope":"runtime"},{"ecosystem":"pypi","name":"huggingface-hub","versionSpec":">=1.31.0","scope":"runtime"},{"ecosystem":"pypi","name":"mcp","versionSpec":"<3.0.0,>=2.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"mistral-common","versionSpec":">=1.11.6","scope":"runtime"},{"ecosystem":"pypi","name":"openai","versionSpec":">=2.25.0","scope":"runtime"},{"ecosystem":"pypi","name":"outlines-core","versionSpec":"==0.2.14","scope":"runtime"},{"ecosystem":"pypi","name":"safetensors","versionSpec":">=0.6.2","scope":"runtime"},{"ecosystem":"pypi","name":"smg-grpc-servicer","versionSpec":">=0.5.2","scope":"extra:grpc"},{"ecosystem":"pypi","name":"tokenizers","versionSpec":">=0.21.1","scope":"runtime"},{"ecosystem":"pypi","name":"transformers","versionSpec":"<5.18.0,>=5.10.4","scope":"runtime"},{"ecosystem":"pypi","name":"xgrammar","versionSpec":"==0.2.7","scope":"runtime"},{"ecosystem":"pypi","name":"humming-kernels","versionSpec":"==0.1.16","scope":"runtime"},{"ecosystem":"pypi","name":"vllm-gguf-plugin","versionSpec":">=0.0.2","scope":"extra:extra-quant"},{"ecosystem":"pypi","name":"zentorch","versionSpec":"==2.13.0.1","scope":"extra:zen"},{"ecosystem":"pypi","name":"aiohttp","versionSpec":">=3.13.3","scope":"runtime"},{"ecosystem":"pypi","name":"apache-tvm-ffi","versionSpec":"==0.1.11","scope":"runtime"},{"ecosystem":"pypi","name":"av","versionSpec":null,"scope":"extra:audio"},{"ecosystem":"pypi","name":"blake3","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"cachetools","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"cbor2","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"cloudpickle","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"depyf","versionSpec":"==0.20.0","scope":"runtime"},{"ecosystem":"pypi","name":"einops","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"fastapi","versionSpec":"<0.137.0,>=0.133.0","scope":"runtime"},{"ecosystem":"pypi","name":"filelock","versionSpec":">=3.16.1","scope":"runtime"},{"ecosystem":"pypi","name":"flashinfer-python","versionSpec":"==0.7.0.post1","scope":"runtime"},{"ecosystem":"pypi","name":"helion","versionSpec":"==1.4.0","scope":"extra:helion"},{"ecosystem":"pypi","name":"ijson","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"instanttensor","versionSpec":">=0.1.9","scope":"runtime"},{"ecosystem":"pypi","name":"jsonschema","versionSpec":">=4.23.0","scope":"runtime"},{"ecosystem":"pypi","name":"lark","versionSpec":"==1.2.2","scope":"runtime"},{"ecosystem":"pypi","name":"llguidance","versionSpec":"<1.8.0,>=1.7.0","scope":"runtime"},{"ecosystem":"pypi","name":"lm-format-enforcer","versionSpec":"==0.11.3","scope":"runtime"},{"ecosystem":"pypi","name":"matplotlib","versionSpec":null,"scope":"extra:bench"},{"ecosystem":"pypi","name":"model-hosting-container-standards","versionSpec":"<1.0.0,>=0.1.14","scope":"runtime"},{"ecosystem":"pypi","name":"msgspec","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"ninja","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"numba","versionSpec":"==0.65.0","scope":"runtime"},{"ecosystem":"pypi","name":"numpy","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"nvidia-cudnn-frontend","versionSpec":">=1.19.1","scope":"runtime"},{"ecosystem":"pypi","name":"nvidia-cutlass-dsl","versionSpec":"==4.7.1","scope":"runtime"},{"ecosystem":"pypi","name":"nvidia-deepstream-videodecode-cu13","versionSpec":">=9.0.2","scope":"extra:deepstream"},{"ecosystem":"pypi","name":"nvtx","versionSpec":"==0.2.15","scope":"runtime"},{"ecosystem":"pypi","name":"opencv-python-headless","versionSpec":">=4.13.0","scope":"runtime"},{"ecosystem":"pypi","name":"opentelemetry-api","versionSpec":">=1.27.0","scope":"runtime"},{"ecosystem":"pypi","name":"opentelemetry-exporter-otlp","versionSpec":">=1.27.0","scope":"runtime"},{"ecosystem":"pypi","name":"opentelemetry-sdk","versionSpec":">=1.27.0","scope":"runtime"},{"ecosystem":"pypi","name":"opentelemetry-semantic-conventions-ai","versionSpec":">=0.4.1","scope":"runtime"},{"ecosystem":"pypi","name":"oss-harmony","versionSpec":">=0.0.11","scope":"runtime"},{"ecosystem":"pypi","name":"pandas","versionSpec":null,"scope":"extra:bench"},{"ecosystem":"pypi","name":"partial-json-parser","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"pillow","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"plotly","versionSpec":null,"scope":"extra:bench"},{"ecosystem":"pypi","name":"prometheus-client","versionSpec":">=0.18.0","scope":"runtime"},{"ecosystem":"pypi","name":"prometheus-fastapi-instrumentator","versionSpec":">=8.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"protobuf","versionSpec":"!=6.30.*,!=6.31.*,!=6.32.*,!=6.33.0.*,!=6.33.1.*,!=6.33.2.*,!=6.33.3.*,!=6.33.4.*,>=5.29.6","scope":"runtime"},{"ecosystem":"pypi","name":"psutil","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"pybase64","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"py-cpuinfo","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"pydantic","versionSpec":">=2.12.0","scope":"runtime"},{"ecosystem":"pypi","name":"pynvvideocodec","versionSpec":"==2.0.4","scope":"runtime"},{"ecosystem":"pypi","name":"python-json-logger","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"pyyaml","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"pyzmq","versionSpec":">=25.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"quack-kernels","versionSpec":"==0.6.5","scope":"runtime"},{"ecosystem":"pypi","name":"regex","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"requests","versionSpec":">=2.26.0","scope":"runtime"},{"ecosystem":"pypi","name":"runai-model-streamer","versionSpec":">=0.15.7","scope":"extra:runai"},{"ecosystem":"pypi","name":"scipy","versionSpec":null,"scope":"extra:bench"},{"ecosystem":"pypi","name":"seaborn","versionSpec":null,"scope":"extra:bench"},{"ecosystem":"pypi","name":"sentencepiece","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"setproctitle","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"setuptools","versionSpec":"<81.0.0,>=77.0.3","scope":"runtime"},{"ecosystem":"pypi","name":"six","versionSpec":">=1.16.0","scope":"runtime"},{"ecosystem":"pypi","name":"soundfile","versionSpec":null,"scope":"extra:audio"},{"ecosystem":"pypi","name":"soxr","versionSpec":null,"scope":"extra:audio"},{"ecosystem":"pypi","name":"starlette","versionSpec":">=1.0.1","scope":"runtime"},{"ecosystem":"pypi","name":"tensorizer","versionSpec":"==2.10.1","scope":"extra:tensorizer"},{"ecosystem":"pypi","name":"tiktoken","versionSpec":">=0.6.0","scope":"runtime"},{"ecosystem":"pypi","name":"tilelang","versionSpec":"==0.1.12","scope":"runtime"},{"ecosystem":"pypi","name":"tokenspeed-mla","versionSpec":"==0.1.8","scope":"runtime"},{"ecosystem":"pypi","name":"torch","versionSpec":"==2.13.0","scope":"runtime"},{"ecosystem":"pypi","name":"torchaudio","versionSpec":"==2.11.0","scope":"runtime"},{"ecosystem":"pypi","name":"torchcodec","versionSpec":">=0.14","scope":"runtime"},{"ecosystem":"pypi","name":"torchvision","versionSpec":"==0.28.0","scope":"runtime"},{"ecosystem":"pypi","name":"tqdm","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"typing-extensions","versionSpec":">=4.10","scope":"runtime"},{"ecosystem":"pypi","name":"watchfiles","versionSpec":null,"scope":"runtime"}],"advisories":[{"id":"a7ef43c7-3fd4-4754-8179-9bf2dab44ab6","url":"https://aisecwatch.com/issues/a7ef43c7-3fd4-4754-8179-9bf2dab44ab6","cveId":"CVE-2026-105758","title":"GHSA-x6mc-67gf-chw4: vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach","headline":null,"severity":"medium","publishedAt":"2026-10-05T23:42:59.000Z","affected":["vllm@>= 0.24.0, < 0.30.0 (fixed: 0.30.0)"],"epssScore":0.00303,"matchedBy":"ecosystem"},{"id":"9a5d4781-24cc-4005-9a39-e88ae3c759be","url":"https://aisecwatch.com/issues/9a5d4781-24cc-4005-9a39-e88ae3c759be","cveId":"CVE-2026-105760","title":"GHSA-58v5-2m8f-94pr: vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion","headline":null,"severity":"medium","publishedAt":"2026-10-05T23:42:55.000Z","affected":["vllm@>= 0.23.0rc2, < 0.30.0 (fixed: 0.30.0)"],"epssScore":0.00302,"matchedBy":"ecosystem"},{"id":"d60747e4-2dae-4873-9366-7b3929e04073","url":"https://aisecwatch.com/issues/d60747e4-2dae-4873-9366-7b3929e04073","cveId":"CVE-2026-105754","title":"GHSA-ph72-cqr5-qpp7: vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features","headline":null,"severity":"medium","publishedAt":"2026-10-05T23:42:50.000Z","affected":["vllm@< 0.30.0 (fixed: 0.30.0)"],"epssScore":0.00269,"matchedBy":"ecosystem"},{"id":"c88c3c60-3772-4363-adf0-ecb261768e41","url":"https://aisecwatch.com/issues/c88c3c60-3772-4363-adf0-ecb261768e41","cveId":"CVE-2026-105757","title":"GHSA-85xf-c7hm-whqw: vLLM: Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service (3 sites)","headline":null,"severity":"medium","publishedAt":"2026-10-05T23:42:44.000Z","affected":["vllm@< 0.30.0 (fixed: 0.30.0)"],"epssScore":0.00314,"matchedBy":"ecosystem"},{"id":"4eeacfc6-0ee7-4e8e-8d88-445fdf4b1240","url":"https://aisecwatch.com/issues/4eeacfc6-0ee7-4e8e-8d88-445fdf4b1240","cveId":"CVE-2026-105755","title":"GHSA-2phq-3phc-84px: vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`","headline":null,"severity":"medium","publishedAt":"2026-10-05T23:42:39.000Z","affected":["vllm@< 0.30.0 (fixed: 0.30.0)"],"epssScore":0.00202,"matchedBy":"ecosystem"},{"id":"ac355ee9-ff2f-45ac-bfde-82e2679b84ff","url":"https://aisecwatch.com/issues/ac355ee9-ff2f-45ac-bfde-82e2679b84ff","cveId":"CVE-2026-105756","title":"GHSA-2823-qmq8-rwvj: vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service","headline":null,"severity":"medium","publishedAt":"2026-10-05T23:42:34.000Z","affected":["vllm@< 0.30.0 (fixed: 0.30.0)"],"epssScore":0.00314,"matchedBy":"ecosystem"},{"id":"9eb610b1-3590-4426-8047-cff25abff510","url":"https://aisecwatch.com/issues/9eb610b1-3590-4426-8047-cff25abff510","cveId":"CVE-2026-105753","title":"CVE-2026-105753: vLLM is an inference and serving engine for large language models. Prior to 0.28.0, the default mirrored multimodal LRU…","headline":"vLLM denial of service via multimodal cache hash reuse","severity":"medium","publishedAt":"2026-10-05T23:17:01.867Z","affected":["vllm@< 0.28.0 (fixed: 0.28.0)"],"epssScore":0.00427,"matchedBy":"ecosystem"},{"id":"7b97b299-f7ba-4f2b-8174-2a5d7f2287f1","url":"https://aisecwatch.com/issues/7b97b299-f7ba-4f2b-8174-2a5d7f2287f1","cveId":"CVE-2026-105752","title":"CVE-2026-105752: vLLM is an inference and serving engine for large language models. Prior to 0.30.0, Harmony tool continuations…","headline":"vLLM prefix cache isolation bypass in Harmony tool continuations","severity":"low","publishedAt":"2026-10-05T23:17:01.710Z","affected":["vllm@< 0.30.0 (fixed: 0.30.0)"],"epssScore":0.00216,"matchedBy":"ecosystem"},{"id":"34748d31-8306-47e5-9b8e-2bad5ece8277","url":"https://aisecwatch.com/issues/34748d31-8306-47e5-9b8e-2bad5ece8277","cveId":"CVE-2026-69147","title":"CVE-2026-69147: vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions…","headline":"vLLM GPU memory exhaustion through request-selected video decoder backend","severity":"medium","publishedAt":"2026-09-16T18:17:11.770Z","affected":["vllm@< 0.28.0 (fixed: 0.28.0)"],"epssScore":0.00583,"matchedBy":"ecosystem"},{"id":"a343f17d-768d-481d-8f34-cd6771155fa1","url":"https://aisecwatch.com/issues/a343f17d-768d-481d-8f34-cd6771155fa1","cveId":"CVE-2026-57173","title":"CVE-2026-57173: vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for…","headline":"vLLM input_audio path allows memory exhaustion","severity":"medium","publishedAt":"2026-09-16T17:17:24.603Z","affected":["vllm@<= 0.23.0 (fixed: 0.24.0)"],"epssScore":0.0073,"matchedBy":"ecosystem"},{"id":"4911c5f3-f942-4cf4-9d0b-6cf2b553f9bc","url":"https://aisecwatch.com/issues/4911c5f3-f942-4cf4-9d0b-6cf2b553f9bc","cveId":"CVE-2026-73560","title":"CVE-2026-73560: vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor…","headline":null,"severity":"medium","publishedAt":"2026-08-17T21:16:48.960Z","affected":["vllm@< 0.26.0 (fixed: 0.26.0)"],"epssScore":0.00407,"matchedBy":"ecosystem"},{"id":"e98e1367-f185-4b87-bc9b-a23cbf6b8be2","url":"https://aisecwatch.com/issues/e98e1367-f185-4b87-bc9b-a23cbf6b8be2","cveId":"CVE-2026-71486","title":"CVE-2026-71486: vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and…","headline":"vLLM resource exhaustion through derender endpoints","severity":"medium","publishedAt":"2026-08-17T20:16:45.927Z","affected":["vllm@< 0.26.0 (fixed: 0.26.0)"],"epssScore":0.00374,"matchedBy":"ecosystem"},{"id":"e2bd92eb-372a-468e-ad65-1e8741ec486d","url":"https://aisecwatch.com/issues/e2bd92eb-372a-468e-ad65-1e8741ec486d","cveId":"CVE-2026-73559","title":"CVE-2026-73559: vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions…","headline":"vLLM completions endpoint resource exhaustion through unbounded prompt list","severity":"medium","publishedAt":"2026-08-13T16:19:05.863Z","affected":["vllm@>= 0.19.0, < 0.26.0 (fixed: 0.26.0)"],"epssScore":0.00583,"matchedBy":"ecosystem"},{"id":"b903fe08-b93d-4373-a11d-d37a5cb17e2b","url":"https://aisecwatch.com/issues/b903fe08-b93d-4373-a11d-d37a5cb17e2b","cveId":"CVE-2026-73558","title":"CVE-2026-73558: vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x *…","headline":"vLLM integer overflow in activation kernel leaks batched inference results","severity":"medium","publishedAt":"2026-08-13T15:20:18.220Z","affected":["vllm@< 0.27.0 (fixed: 0.27.0)"],"epssScore":0.00414,"matchedBy":"ecosystem"},{"id":"6d139325-5929-4caf-8196-d496833092a2","url":"https://aisecwatch.com/issues/6d139325-5929-4caf-8196-d496833092a2","cveId":"CVE-2026-73557","title":"CVE-2026-73557: vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds…","headline":"vLLM race condition bypasses sparse tensor validation in prompt_embeds","severity":"high","publishedAt":"2026-08-13T15:20:18.080Z","affected":["vllm@>= 0.21.0, < 0.26.0 (fixed: 0.26.0)"],"epssScore":0.00404,"matchedBy":"ecosystem"},{"id":"2ca81c7a-3993-4a1b-ac2e-0ce55dcfa4b7","url":"https://aisecwatch.com/issues/2ca81c7a-3993-4a1b-ac2e-0ce55dcfa4b7","cveId":"CVE-2026-73556","title":"CVE-2026-73556: vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex…","headline":"vLLM regex denial of service via structured_outputs.regex on /v1/completions","severity":"medium","publishedAt":"2026-08-13T15:20:17.927Z","affected":["vllm@< 0.26.0 (fixed: 0.26.0)"],"epssScore":0.00515,"matchedBy":"ecosystem"},{"id":"0c0fb401-a84a-41b0-9ab6-72fad19b95b3","url":"https://aisecwatch.com/issues/0c0fb401-a84a-41b0-9ab6-72fad19b95b3","cveId":"CVE-2026-73555","title":"CVE-2026-73555: vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in…","headline":"vLLM information disclosure via malformed JSON requests","severity":"medium","publishedAt":"2026-08-13T15:20:17.773Z","affected":["vllm@< 0.26.0 (fixed: 0.26.0)"],"epssScore":0.00413,"matchedBy":"ecosystem"},{"id":"41404ae5-a355-4ea2-adb9-f7ef5af461c4","url":"https://aisecwatch.com/issues/41404ae5-a355-4ea2-adb9-f7ef5af461c4","cveId":"CVE-2026-55574","title":"CVE-2026-55574: vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the…","headline":"vLLM denial of service through structured_outputs regex parameter","severity":"high","publishedAt":"2026-07-06T21:16:57.347Z","affected":["vllm@< 0.24.0 (fixed: 0.24.0)"],"epssScore":0.00583,"matchedBy":"ecosystem"},{"id":"2ba12c77-2687-43c7-adbc-0c285e06e34b","url":"https://aisecwatch.com/issues/2ba12c77-2687-43c7-adbc-0c285e06e34b","cveId":"CVE-2026-55514","title":"CVE-2026-55514: vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in…","headline":"vLLM crash via pure prompt embeds in /v1/completions requests","severity":"high","publishedAt":"2026-07-06T21:16:57.207Z","affected":["vllm@>= 0.12.0, < 0.24.0 (fixed: 0.24.0)"],"epssScore":0.00665,"matchedBy":"ecosystem"},{"id":"9db90a97-9702-48de-9fb4-c01e63c7cf9a","url":"https://aisecwatch.com/issues/9db90a97-9702-48de-9fb4-c01e63c7cf9a","cveId":"CVE-2026-54234","title":"CVE-2026-54234: vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal…","headline":"vLLM denial of service through speculative decoding over gRPC Generate","severity":"high","publishedAt":"2026-07-06T21:16:56.477Z","affected":["vllm@>= 0.17.1, < 0.24.0 (fixed: 0.24.0)"],"epssScore":0.00616,"matchedBy":"ecosystem"},{"id":"402bf3d7-d8a5-410b-b4e7-d9b4f780eea2","url":"https://aisecwatch.com/issues/402bf3d7-d8a5-410b-b4e7-d9b4f780eea2","cveId":"CVE-2026-55646","title":"CVE-2026-55646: vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions…","headline":"vLLM audio transcription routes allow memory exhaustion via oversized uploads","severity":"medium","publishedAt":"2026-07-06T20:16:37.663Z","affected":["vllm@>= 0.22.0, < 0.24.0 (fixed: 0.24.0)"],"epssScore":0.00519,"matchedBy":"ecosystem"},{"id":"6fa7a9d2-9ac5-471b-8e3e-ab7d191bc9bb","url":"https://aisecwatch.com/issues/6fa7a9d2-9ac5-471b-8e3e-ab7d191bc9bb","cveId":"CVE-2026-56340","title":"CVE-2026-56340: vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because…","headline":"vLLM multimodal embeddings processing missing sparse tensor validation","severity":"high","publishedAt":"2026-06-20T19:16:23.567Z","affected":["vllm@>= 0.10.2, < 0.13.0 (fixed: 0.13.0)"],"epssScore":0.00644,"matchedBy":"ecosystem"},{"id":"dffb878b-7fe7-40a6-be71-5d7d5992664e","url":"https://aisecwatch.com/issues/dffb878b-7fe7-40a6-be71-5d7d5992664e","cveId":"CVE-2026-54233","title":"GHSA-6pr9-rp53-2pmc: vLLM: OOM Denial of Service via Audio Decompression Bomb","headline":null,"severity":"medium","publishedAt":"2026-06-17T14:06:22.000Z","affected":["vllm@<= 0.23.0"],"epssScore":0.00422,"matchedBy":"ecosystem"},{"id":"db53f23a-bca9-4d7f-bdd5-e405d4c58c12","url":"https://aisecwatch.com/issues/db53f23a-bca9-4d7f-bdd5-e405d4c58c12","cveId":"CVE-2026-54236","title":"GHSA-hgg8-fqqc-vfmw: vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router","headline":null,"severity":"medium","publishedAt":"2026-06-17T14:04:09.000Z","affected":["vllm@<= 0.23.0"],"epssScore":0.00927,"matchedBy":"ecosystem"},{"id":"56d482da-641e-43c7-ad60-88718cf5f946","url":"https://aisecwatch.com/issues/56d482da-641e-43c7-ad60-88718cf5f946","cveId":"CVE-2026-53923","title":"GHSA-5jv2-g5wq-cmr4: vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving","headline":null,"severity":"medium","publishedAt":"2026-06-17T14:03:11.000Z","affected":["vllm@>= 0.5.5, <= 0.23.0"],"epssScore":0.00484,"matchedBy":"ecosystem"},{"id":"5a27ee9e-cb86-4dc9-a013-fc8e66b2b0c1","url":"https://aisecwatch.com/issues/5a27ee9e-cb86-4dc9-a013-fc8e66b2b0c1","cveId":null,"title":"GHSA-8jr5-v98p-w75m: vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations","headline":null,"severity":"medium","publishedAt":"2026-06-17T14:02:42.000Z","affected":["vllm@>= 0.11.0, <= 0.23.0"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"36b43c03-af06-4667-948d-974b43d4d645","url":"https://aisecwatch.com/issues/36b43c03-af06-4667-948d-974b43d4d645","cveId":"CVE-2026-54235","title":"GHSA-7h4p-rffg-7823: vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels","headline":null,"severity":"medium","publishedAt":"2026-06-17T14:02:22.000Z","affected":["vllm@<= 0.23.0"],"epssScore":0.0045,"matchedBy":"ecosystem"},{"id":"f858b34a-ab09-408b-a7be-8418c0bb4b10","url":"https://aisecwatch.com/issues/f858b34a-ab09-408b-a7be-8418c0bb4b10","cveId":"CVE-2026-48746","title":"GHSA-94f4-hr76-p5j6: vLLM: OpenAI auth bypass","headline":null,"severity":"critical","publishedAt":"2026-06-16T17:36:41.000Z","affected":["vllm@>= 0.3.0, < 0.22.0 (fixed: 0.22.0)"],"epssScore":0.01152,"matchedBy":"ecosystem"},{"id":"e1fd34b5-73a5-40b6-a1fe-74a6c9a504eb","url":"https://aisecwatch.com/issues/e1fd34b5-73a5-40b6-a1fe-74a6c9a504eb","cveId":"CVE-2026-41523","title":"GHSA-q8gq-377p-jq3r: vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution","headline":null,"severity":"high","publishedAt":"2026-06-16T17:34:49.000Z","affected":["vllm@< 0.22.0 (fixed: 0.22.0)"],"epssScore":0.00913,"matchedBy":"ecosystem"},{"id":"2c7ca275-3e1f-49ab-857d-8bf7be6794e9","url":"https://aisecwatch.com/issues/2c7ca275-3e1f-49ab-857d-8bf7be6794e9","cveId":"CVE-2026-5497","title":"CVE-2026-5497: vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded…","headline":"vLLM out-of-memory denial of service via unbounded video frames in data URLs","severity":"high","publishedAt":"2026-06-11T10:16:21.903Z","affected":["vllm@>= 0.8.0, < 0.19.0 (fixed: 0.19.0)"],"epssScore":0.00896,"matchedBy":"ecosystem"},{"id":"ddfbc3e6-ecf1-4300-bf71-6e3a76904f55","url":"https://aisecwatch.com/issues/ddfbc3e6-ecf1-4300-bf71-6e3a76904f55","cveId":"CVE-2026-47155","title":"GHSA-3ww4-5jv9-j5gm: vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors","headline":null,"severity":"medium","publishedAt":"2026-06-10T17:11:38.000Z","affected":["vllm@< 0.22.0 (fixed: 0.22.0)"],"epssScore":0.00249,"matchedBy":"ecosystem"},{"id":"9476f42f-6381-496a-819c-0aa34d2d82c0","url":"https://aisecwatch.com/issues/9476f42f-6381-496a-819c-0aa34d2d82c0","cveId":"CVE-2026-9540","title":"CVE-2026-9540: A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component…","headline":"vllm-project vllm denial of service in OpenAI-compatible serving path","severity":"medium","publishedAt":"2026-05-26T14:16:45.803Z","affected":["vllm@<= 0.19.0"],"epssScore":0.00724,"matchedBy":"ecosystem"},{"id":"2440958b-5d4a-4acc-8ad5-33fdd6fa361b","url":"https://aisecwatch.com/issues/2440958b-5d4a-4acc-8ad5-33fdd6fa361b","cveId":"CVE-2026-44223","title":"GHSA-83vm-p52w-f9pw: vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters","headline":null,"severity":"medium","publishedAt":"2026-05-06T21:45:51.000Z","affected":["vllm@>= 0.18.0, < 0.20.0 (fixed: 0.20.0)"],"epssScore":0.00426,"matchedBy":"ecosystem"},{"id":"a45197ed-95a7-4ae0-9435-1112b6e4ba95","url":"https://aisecwatch.com/issues/a45197ed-95a7-4ae0-9435-1112b6e4ba95","cveId":"CVE-2026-44222","title":"GHSA-hpv8-x276-m59f: vLLM Vulnerable to Remote DoS via Special-Token Placeholders","headline":null,"severity":"medium","publishedAt":"2026-05-05T22:21:41.000Z","affected":["vllm@>= 0.6.1, < 0.20.0 (fixed: 0.20.0)"],"epssScore":0.00455,"matchedBy":"ecosystem"},{"id":"17bc07d8-8072-474d-91a3-e3df8f193110","url":"https://aisecwatch.com/issues/17bc07d8-8072-474d-91a3-e3df8f193110","cveId":"CVE-2026-7141","title":"CVE-2026-7141: A vulnerability was found in vllm up to 0.19.0. The affected element is the function has_mamba_layers of the file…","headline":"vllm uninitialized resource in has_mamba_layers of KV Block Handler","severity":"medium","publishedAt":"2026-04-27T17:16:45.637Z","affected":["vllm@< 0.19.1 (fixed: 0.19.1)"],"epssScore":0.00478,"matchedBy":"ecosystem"},{"id":"289ecde7-abad-4e08-8dc6-5d9aa45a9b53","url":"https://aisecwatch.com/issues/289ecde7-abad-4e08-8dc6-5d9aa45a9b53","cveId":"CVE-2026-34755","title":"GHSA-pq5c-rjhq-qp7p: vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing","headline":null,"severity":"medium","publishedAt":"2026-04-03T21:51:35.000Z","affected":["vllm@>= 0.7.0, < 0.19.0 (fixed: 0.19.0)"],"epssScore":0.00843,"matchedBy":"ecosystem"},{"id":"2dd6125f-89a1-45b2-b273-8e92669370b3","url":"https://aisecwatch.com/issues/2dd6125f-89a1-45b2-b273-8e92669370b3","cveId":"CVE-2026-34753","title":"GHSA-pf3h-qjgv-vcpr: vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `","headline":null,"severity":"medium","publishedAt":"2026-04-03T21:51:00.000Z","affected":["vllm@>= 0.16.0, < 0.19.0 (fixed: 0.19.0)"],"epssScore":0.00305,"matchedBy":"ecosystem"},{"id":"bff55a5b-2c0b-465a-92ee-437ca396f40a","url":"https://aisecwatch.com/issues/bff55a5b-2c0b-465a-92ee-437ca396f40a","cveId":"CVE-2026-34756","title":"GHSA-3mwp-wvh9-7528: vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server","headline":null,"severity":"medium","publishedAt":"2026-04-03T15:35:48.000Z","affected":["vllm@>= 0.1.0, < 0.19.0 (fixed: 0.19.0)"],"epssScore":0.00766,"matchedBy":"ecosystem"},{"id":"97083055-abe2-4a31-b778-7ee97759ddab","url":"https://aisecwatch.com/issues/97083055-abe2-4a31-b778-7ee97759ddab","cveId":"CVE-2026-34760","title":"CVE-2026-34760: vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0…","headline":"vLLM audio mono downmixing mismatch with ITU-R BS.775-4 standard","severity":"medium","publishedAt":"2026-04-02T20:16:25.437Z","affected":["vllm@>= 0.5.5, < 0.18.0 (fixed: 0.18.0)"],"epssScore":0.00476,"matchedBy":"ecosystem"},{"id":"cba2a887-3f39-45c0-a9ef-bde286c34c5d","url":"https://aisecwatch.com/issues/cba2a887-3f39-45c0-a9ef-bde286c34c5d","cveId":"CVE-2026-27893","title":"CVE-2026-27893: vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to…","headline":"vLLM remote code execution through hardcoded trust_remote_code in model loading","severity":"high","publishedAt":"2026-03-27T00:16:22.333Z","affected":["vllm@>= 0.10.1, < 0.18.0 (fixed: 0.18.0)"],"epssScore":0.01808,"matchedBy":"ecosystem"},{"id":"719571ec-0132-4380-998d-102caab6e3ce","url":"https://aisecwatch.com/issues/719571ec-0132-4380-998d-102caab6e3ce","cveId":"CVE-2026-25960","title":"GHSA-v359-jj2v-j536: vLLM has SSRF Protection Bypass","headline":null,"severity":"medium","publishedAt":"2026-03-09T19:55:32.000Z","affected":["vllm@>= 0.15.1, < 0.17.0 (fixed: 0.17.0)"],"epssScore":0.00746,"matchedBy":"ecosystem"},{"id":"6a50c90c-0e5c-4606-88f5-d835579c6625","url":"https://aisecwatch.com/issues/6a50c90c-0e5c-4606-88f5-d835579c6625","cveId":"CVE-2026-22778","title":"CVE-2026-22778: vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid…","headline":"vLLM information leak of heap address via multimodal endpoint image errors","severity":"critical","publishedAt":"2026-02-03T04:16:06.700Z","affected":["vllm@>= 0.8.3, < 0.14.1 (fixed: 0.14.1)"],"epssScore":0.1116,"matchedBy":"ecosystem"},{"id":"940d3644-1c49-4259-abd1-5b22dd1ae994","url":"https://aisecwatch.com/issues/940d3644-1c49-4259-abd1-5b22dd1ae994","cveId":"CVE-2026-24779","title":"CVE-2026-24779: vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side…","headline":"vLLM server-side request forgery in MediaConnector via URL host bypass","severity":"high","publishedAt":"2026-01-28T03:15:57.280Z","affected":["vllm@< 0.14.1 (fixed: 0.14.1)"],"epssScore":0.00588,"matchedBy":"ecosystem"},{"id":"5e13d5f4-fae3-46f7-812b-d7aa8b6b642a","url":"https://aisecwatch.com/issues/5e13d5f4-fae3-46f7-812b-d7aa8b6b642a","cveId":"CVE-2026-22807","title":"CVE-2026-22807: vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to…","headline":"vLLM arbitrary code execution through Hugging Face auto_map model loading","severity":"high","publishedAt":"2026-01-22T03:15:49.077Z","affected":["vllm@>= 0.10.1, < 0.14.0 (fixed: 0.14.0)"],"epssScore":0.0083,"matchedBy":"ecosystem"},{"id":"65eef340-4948-4271-88d8-a92c8345ca45","url":"https://aisecwatch.com/issues/65eef340-4948-4271-88d8-a92c8345ca45","cveId":"CVE-2026-22773","title":"CVE-2026-22773: vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0…","headline":"vLLM engine crash via crafted 1x1 pixel image in Idefics3 multimodal models","severity":"medium","publishedAt":"2026-01-10T12:16:03.527Z","affected":["vllm@>= 0.6.4, < 0.12.0 (fixed: 0.12.0)"],"epssScore":0.00442,"matchedBy":"ecosystem"},{"id":"0f16f139-cafd-4327-889a-2bb9c918e2c9","url":"https://aisecwatch.com/issues/0f16f139-cafd-4327-889a-2bb9c918e2c9","cveId":"CVE-2025-66448","title":"CVE-2025-66448: vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote…","headline":"vLLM remote code execution through Nemotron_Nano_VL_Config auto_map entry","severity":"high","publishedAt":"2025-12-02T04:15:54.213Z","affected":["vllm@< 0.11.1 (fixed: 0.11.1)"],"epssScore":0.0066,"matchedBy":"ecosystem"},{"id":"aa27593b-546b-4d27-854a-7bd3ba2b9a16","url":"https://aisecwatch.com/issues/aa27593b-546b-4d27-854a-7bd3ba2b9a16","cveId":"CVE-2025-62426","title":"CVE-2025-62426: vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, the…","headline":"vLLM denial of service via chat_template_kwargs in chat endpoints","severity":"medium","publishedAt":"2025-11-21T07:15:43.570Z","affected":["vllm@>= 0.5.5, < 0.11.1 (fixed: 0.11.1)"],"epssScore":0.00368,"matchedBy":"ecosystem"},{"id":"95c9f506-e4b4-45a6-b010-fe92cbe939a5","url":"https://aisecwatch.com/issues/95c9f506-e4b4-45a6-b010-fe92cbe939a5","cveId":"CVE-2025-62372","title":"CVE-2025-62372: vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users…","headline":"vLLM engine crash via malformed multimodal embedding input shape","severity":"medium","publishedAt":"2025-11-21T07:15:43.393Z","affected":["vllm@>= 0.5.5, < 0.11.1 (fixed: 0.11.1)"],"epssScore":0.00382,"matchedBy":"ecosystem"},{"id":"b126f34e-3d4e-4122-91e3-677d04348f88","url":"https://aisecwatch.com/issues/b126f34e-3d4e-4122-91e3-677d04348f88","cveId":"CVE-2025-62164","title":"CVE-2025-62164: vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a…","headline":"vLLM memory corruption through prompt embeddings in Completions API","severity":"high","publishedAt":"2025-11-21T07:15:43.193Z","affected":["vllm@>= 0.10.2, < 0.11.1 (fixed: 0.11.1)"],"epssScore":0.00929,"matchedBy":"ecosystem"},{"id":"74c258db-a82a-401d-b12c-6c9152fba44c","url":"https://aisecwatch.com/issues/74c258db-a82a-401d-b12c-6c9152fba44c","cveId":"CVE-2025-6242","title":"CVE-2025-6242: A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's…","headline":"vLLM SSRF in MediaConnector via load_from_url methods","severity":"high","publishedAt":"2025-10-08T00:15:36.187Z","affected":["vllm@>= 0.5.0, < 0.11.0 (fixed: 0.11.0)"],"epssScore":0.00247,"matchedBy":"ecosystem"},{"id":"f55539f4-dd2f-4b77-8829-2f1b6e08931d","url":"https://aisecwatch.com/issues/f55539f4-dd2f-4b77-8829-2f1b6e08931d","cveId":"CVE-2025-59425","title":"CVE-2025-59425: vLLM is an inference and serving engine for large language models (LLMs). Before version 0.11.0rc2, the API key support…","headline":"vLLM API key validation vulnerable to timing attack","severity":"high","publishedAt":"2025-10-07T18:15:38.950Z","affected":["vllm@< 0.11.0 (fixed: 0.11.0)"],"epssScore":0.00566,"matchedBy":"ecosystem"},{"id":"064a6ec1-84d2-4986-b63f-15d024dedeb7","url":"https://aisecwatch.com/issues/064a6ec1-84d2-4986-b63f-15d024dedeb7","cveId":"CVE-2025-48956","title":"CVE-2025-48956: vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.10.1.1, a Denial of…","headline":"vLLM denial of service through oversized HTTP GET request header","severity":"high","publishedAt":"2025-08-21T19:15:32.230Z","affected":["vllm@>= 0.1.0, < 0.10.1.1 (fixed: 0.10.1.1)"],"epssScore":0.0056,"matchedBy":"ecosystem"},{"id":"560b8a18-71a4-4f16-a16c-51a66d6dbbc2","url":"https://aisecwatch.com/issues/560b8a18-71a4-4f16-a16c-51a66d6dbbc2","cveId":"CVE-2025-48944","title":"CVE-2025-48944: vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0…","headline":"vLLM crash through malformed tool input on /v1/chat/completions","severity":"medium","publishedAt":"2025-05-30T23:15:30.433Z","affected":["vllm@>= 0.8.0, < 0.9.0 (fixed: 0.9.0)"],"epssScore":0.00529,"matchedBy":"ecosystem"},{"id":"7458be3c-d4de-4b4b-88bf-92135aa5281b","url":"https://aisecwatch.com/issues/7458be3c-d4de-4b4b-88bf-92135aa5281b","cveId":"CVE-2025-48943","title":"CVE-2025-48943: vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have…","headline":"vLLM denial of service through invalid regex in structured output","severity":"medium","publishedAt":"2025-05-30T23:15:30.280Z","affected":["vllm@>= 0.8.0, < 0.9.0 (fixed: 0.9.0)"],"epssScore":0.00487,"matchedBy":"ecosystem"},{"id":"200aba0e-1ff4-4a78-9323-9464867c58ef","url":"https://aisecwatch.com/issues/200aba0e-1ff4-4a78-9323-9464867c58ef","cveId":"CVE-2025-48942","title":"CVE-2025-48942: vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0…","headline":"vLLM server crash via invalid json_schema in /v1/completions Guided Param","severity":"medium","publishedAt":"2025-05-30T23:15:30.130Z","affected":["vllm@>= 0.8.0, < 0.9.0 (fixed: 0.9.0)"],"epssScore":0.00551,"matchedBy":"ecosystem"},{"id":"242ae08a-d118-40fb-ab9b-b76547ad7f51","url":"https://aisecwatch.com/issues/242ae08a-d118-40fb-ab9b-b76547ad7f51","cveId":"CVE-2025-48887","title":"CVE-2025-48887: vLLM, an inference and serving engine for large language models (LLMs), has a Regular Expression Denial of Service…","headline":"vLLM regular expression denial of service in pythonic tool parser","severity":"medium","publishedAt":"2025-05-30T22:15:32.500Z","affected":["vllm@>= 0.6.4, < 0.9.0 (fixed: 0.9.0)"],"epssScore":0.00518,"matchedBy":"ecosystem"},{"id":"61d93112-e429-4bf1-ab08-26cf89d05af4","url":"https://aisecwatch.com/issues/61d93112-e429-4bf1-ab08-26cf89d05af4","cveId":"CVE-2025-46722","title":"CVE-2025-46722: vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before…","headline":"vLLM hash collisions in multimodal image hashing via raw pixel bytes","severity":"medium","publishedAt":"2025-05-29T21:15:21.523Z","affected":["vllm@>= 0.7.0, < 0.9.0 (fixed: 0.9.0)"],"epssScore":0.00324,"matchedBy":"ecosystem"},{"id":"eb9a26d8-3b5b-4540-8ed9-839f58fe1d11","url":"https://aisecwatch.com/issues/eb9a26d8-3b5b-4540-8ed9-839f58fe1d11","cveId":"CVE-2025-46570","title":"CVE-2025-46570: vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is…","headline":"vLLM timing side channel in prefix cache matching during prefill","severity":"low","publishedAt":"2025-05-29T21:15:21.327Z","affected":["vllm@< 0.9.0 (fixed: 0.9.0)"],"epssScore":0.003,"matchedBy":"ecosystem"},{"id":"97c493ed-868b-4e5f-a348-b0828eb14c7c","url":"https://aisecwatch.com/issues/97c493ed-868b-4e5f-a348-b0828eb14c7c","cveId":"CVE-2025-47277","title":"CVE-2025-47277: vLLM, an inference and serving engine for large language models (LLMs), has an issue in versions 0.6.5 through 0.8.4…","headline":"vLLM PyNcclPipe KV cache transfer exposed on all network interfaces","severity":"critical","publishedAt":"2025-05-20T22:15:46.730Z","affected":["vllm@>= 0.6.5, < 0.8.5 (fixed: 0.8.5)"],"epssScore":0.00959,"matchedBy":"ecosystem"},{"id":"8f0f06b0-17b1-4211-a88b-c2befcc85230","url":"https://aisecwatch.com/issues/8f0f06b0-17b1-4211-a88b-c2befcc85230","cveId":"CVE-2025-30165","title":"CVE-2025-30165: vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine…","headline":"vLLM unsafe pickle deserialization in multi-node ZeroMQ communication","severity":"high","publishedAt":"2025-05-06T21:16:11.660Z","affected":["vllm@>= 0.5.2, < 0.10.0 (fixed: 0.10.0)"],"epssScore":0.00495,"matchedBy":"ecosystem"},{"id":"48c9fafb-8e2d-4da7-9b65-6a231b2d5d52","url":"https://aisecwatch.com/issues/48c9fafb-8e2d-4da7-9b65-6a231b2d5d52","cveId":"CVE-2025-46560","title":"CVE-2025-46560: vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.8.0 and…","headline":"vLLM multimodal tokenizer quadratic time complexity resource exhaustion","severity":"medium","publishedAt":"2025-04-30T05:15:52.097Z","affected":["vllm@>= 0.8.0, < 0.8.5 (fixed: 0.8.5)"],"epssScore":0.00524,"matchedBy":"ecosystem"},{"id":"5e0cf75c-d70c-47a0-a234-c72504785fc8","url":"https://aisecwatch.com/issues/5e0cf75c-d70c-47a0-a234-c72504785fc8","cveId":"CVE-2025-32444","title":"CVE-2025-32444: vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and…","headline":"vLLM remote code execution through pickle deserialization over ZeroMQ sockets","severity":"critical","publishedAt":"2025-04-30T05:15:51.953Z","affected":["vllm@>= 0.6.5, < 0.8.5 (fixed: 0.8.5)"],"epssScore":0.01789,"matchedBy":"ecosystem"},{"id":"2387989b-b211-409d-9c0f-ce08fd7b3175","url":"https://aisecwatch.com/issues/2387989b-b211-409d-9c0f-ce08fd7b3175","cveId":"CVE-2025-30202","title":"CVE-2025-30202: vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.5.2 and…","headline":"vLLM denial of service and data exposure via ZeroMQ on multi-node deployment","severity":"high","publishedAt":"2025-04-30T05:15:51.800Z","affected":["vllm@>= 0.5.2, < 0.8.5 (fixed: 0.8.5)"],"epssScore":0.00598,"matchedBy":"ecosystem"},{"id":"bd9b18b7-4e75-432b-9da2-f8afe0549f6c","url":"https://aisecwatch.com/issues/bd9b18b7-4e75-432b-9da2-f8afe0549f6c","cveId":"CVE-2024-9053","title":"CVE-2024-9053: vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core…","headline":"vllm-project vllm RPC server remote code execution via unsafe deserialization","severity":"critical","publishedAt":"2025-03-20T14:15:46.327Z","affected":["vllm@<= 0.6.0"],"epssScore":0.0138,"matchedBy":"ecosystem"},{"id":"84bc0514-088d-4ac1-81be-fb636fc0b039","url":"https://aisecwatch.com/issues/84bc0514-088d-4ac1-81be-fb636fc0b039","cveId":"CVE-2024-11041","title":"CVE-2024-11041: vllm-project vllm version v0.6.2 contains a vulnerability in the MessageQueue.dequeue() API function. The function uses…","headline":"vllm-project vllm remote code execution in MessageQueue.dequeue() via pickle","severity":"critical","publishedAt":"2025-03-20T14:15:23.420Z","affected":["vllm@<= 0.6.2"],"epssScore":0.01555,"matchedBy":"ecosystem"},{"id":"46e3d318-c02a-4eed-90a9-e55d84f2ee77","url":"https://aisecwatch.com/issues/46e3d318-c02a-4eed-90a9-e55d84f2ee77","cveId":"CVE-2025-29783","title":"CVE-2025-29783: vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use…","headline":"vLLM unsafe deserialization over ZMQ/TCP when using Mooncake","severity":"critical","publishedAt":"2025-03-19T20:15:32.477Z","affected":["vllm@>= 0.6.5, < 0.8.0 (fixed: 0.8.0)"],"epssScore":0.00728,"matchedBy":"ecosystem"},{"id":"5c9feea8-f462-44f7-8850-cce545016f58","url":"https://aisecwatch.com/issues/5c9feea8-f462-44f7-8850-cce545016f58","cveId":"CVE-2025-29770","title":"CVE-2025-29770: vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. The outlines library is one of…","headline":"vLLM unbounded filesystem cache growth via outlines guided decoding","severity":"medium","publishedAt":"2025-03-19T20:15:31.977Z","affected":["vllm@< 0.8.0 (fixed: 0.8.0)"],"epssScore":0.00461,"matchedBy":"ecosystem"},{"id":"140be3d5-1cec-40f6-bedc-6c1f38ab6819","url":"https://aisecwatch.com/issues/140be3d5-1cec-40f6-bedc-6c1f38ab6819","cveId":"CVE-2025-25183","title":"CVE-2025-25183: vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Maliciously constructed…","headline":"vLLM prefix caching hash collisions can reuse cache from other prompts","severity":"low","publishedAt":"2025-02-08T01:15:34.083Z","affected":["vllm@< 0.7.2 (fixed: 0.7.2)"],"epssScore":0.00191,"matchedBy":"ecosystem"},{"id":"0b03bbd2-e169-4a8c-9d99-70ac0997b4de","url":"https://aisecwatch.com/issues/0b03bbd2-e169-4a8c-9d99-70ac0997b4de","cveId":"CVE-2025-24357","title":"CVE-2025-24357: vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements…","headline":"vLLM deserialization of untrusted model weights via torch.load","severity":"high","publishedAt":"2025-01-27T23:15:41.523Z","affected":["vllm@< 0.7.0 (fixed: 0.7.0)"],"epssScore":0.00697,"matchedBy":"ecosystem"},{"id":"1e7e651c-cc3f-41c3-9349-854dcebf6c0a","url":"https://aisecwatch.com/issues/1e7e651c-cc3f-41c3-9349-854dcebf6c0a","cveId":"CVE-2024-8939","title":"CVE-2024-8939: A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the…","headline":"ilab model serve denial of service via best_of parameter in vllm JSON API","severity":"medium","publishedAt":"2024-09-17T21:15:11.327Z","affected":["vllm@<= 0.5.0.post1"],"epssScore":0.00233,"matchedBy":"ecosystem"},{"id":"1188331a-d363-41ff-a3ec-d7658ad6bd22","url":"https://aisecwatch.com/issues/1188331a-d363-41ff-a3ec-d7658ad6bd22","cveId":"CVE-2024-8768","title":"CVE-2024-8768: A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server…","headline":"vLLM denial of service through completions API with empty prompt","severity":"high","publishedAt":"2024-09-17T21:15:11.100Z","affected":["vllm@< 0.5.5 (fixed: 0.5.5)"],"epssScore":0.00682,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:53:52.109Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}