vLLM是vLLM开源的一个适用于 LLM 的高吞吐量和内存高效推理和服务引擎。 vLLM 0.8.0至0.9.0之前版本存在输入验证错误漏洞,该漏洞源于调用工具功能时未验证pattern和type字段的意外或畸形输入,可能导致推理工作器崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vllm-project | vllm | >= 0.8.0, < 0.9.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-48887 | 6.5 MEDIUM | vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerabil |
| CVE-2025-48942 | 6.5 MEDIUM | vLLM DOS: Remotely kill vllm over http with invalid JSON schema |
| CVE-2025-48943 | 6.5 MEDIUM | vLLM allows clients to crash the openai server with invalid regex |
No comments yet