在 vllm-project 的 vLLM 版本(至 0.27.1 及更早版本)中确认存在一个漏洞。该漏洞影响组件 Jinja 模板渲染功能中 /v1/chat/completions 文件的未知部分。通过操纵参数 可引发资源消耗问题。该攻击可远程发起。该利用方式已公开披露,可能被利用。旨在修复此问题的拉取请求(Pull Request)目前尚未被接受。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vllm-project | vLLM | 0.27.0 |
cpe:2.3:a:vllm-project:vllm:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet