Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
Vulnerability Description
vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving multimodal models by passing multimodal embedding inputs with correct ndim but incorrect shape (e.g. hidden dimension is wrong), regardless of whether the model is intended to support such inputs (as defined in the Supported Models page). This issue has been patched in version 0.11.1.
CVSS Information
N/A
Vulnerability Type
对数组索引的验证不恰当
Vulnerability Title
vLLM 输入验证错误漏洞
Vulnerability Description
vLLM是vLLM开源的一个适用于 LLM 的高吞吐量和内存高效推理和服务引擎。 vLLM 0.5.5版本至0.11.1之前版本存在输入验证错误漏洞,该漏洞源于多模态嵌入输入处理不当,可能导致引擎崩溃。
CVSS Information
N/A
Vulnerability Type
N/A