vLLM 是用于大型语言模型的推理和服务引擎。从版本 0.19.0 到 0.26.0,vllm/entrypoints/openai/completion/protocol.py 中的 /v1/completions CompletionRequest.prompt 字段接受无限制的 list[str] 或 list[list[int]]。vllm/renderers/inputs/preprocess.py 中的 prompt_to_seq() 以及 vllm/renderers/online_renderer.
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| vllm-project | vllm | >= 0.19.0, < 0.26.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vllm-project | vllm | >= 0.19.0, < 0.26.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73557 | 6.3 MEDIUM | vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts |
| CVE-2026-73555 | 5.3 MEDIUM | vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages |
| CVE-2026-73556 | 5.3 MEDIUM | vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile tim |
| CVE-2026-73558 | 5.3 MEDIUM | vLLM: Cross-User Data Leak Vulnerability |
No comments yet