Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

vllm — Vulnerabilities & Security Advisories 98

All 98 CVE vulnerabilities found in vllm, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting the vLLM software product, a high-throughput inference engine for large language models. It collects advisories related to specific weakness types, covering the period from the project's initial release through the most recent updates. Readers can use this resource to track the vendor's published advisories, understand common vulnerability classes within the codebase, and review the product's historical security record without hunting through individual commit messages or release notes. The collection focuses on flaws in input validation, resource management, and deserialization, reflecting the primary attack surfaces identified by the community. This summary provides a consolidated view of past issues to support risk assessment and patching strategies.

Vendor: vllm-project

CVE ID Title CVSS Severity Published
CVE-2026-105922 vllm-project vLLM Penalty utils.py get_token_bin_counts_and_mask denial of service CWE-404 4.3 Medium 2026-10-06
CVE-2026-105775 vllm-project vLLM Completions Request mamba_mixer2.py conv_ssm_forward out-of-bounds CWE-125 4.3 Medium 2026-10-06
CVE-2026-105760 vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion CWE-400 5.3 Medium 2026-10-05
CVE-2026-105759 vLLM: Unbounded Prometheus label cardinality from attacker-controlled HTTP method tokens in the vLLM Rust frontend metrics middleware (unauthenticated denial of service) CWE-400 5.9 Medium 2026-10-05
CVE-2026-105758 vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach CWE-770 5.3 Medium 2026-10-05
CVE-2026-105757 vLLM: Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service (3 sites) CWE-20 6.5 Medium 2026-10-05
CVE-2026-105756 vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service CWE-20 6.5 Medium 2026-10-05
CVE-2026-105755 vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank` CWE-639 4.2 Medium 2026-10-05
CVE-2026-105754 vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features CWE-20 6.5 Medium 2026-10-05
CVE-2026-105753 vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core CWE-617 6.5 Medium 2026-10-05
CVE-2026-105752 vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle CWE-200 3.1 Low 2026-10-05
CVE-2026-103241 vllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of service CWE-404 5.3 Medium 2026-09-30
CVE-2026-100653 vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation CWE-348 6.5 Medium 2026-09-26
CVE-2026-100654 vLLM before 0.29.0 Denial of Service via out-of-range stop_token_ids CWE-129 6.5 Medium 2026-09-26
CVE-2026-100652 vLLM 0.22.0 through 0.23.0 Denial of Service via stop_token_ids CWE-20 5.9 Medium 2026-09-26
CVE-2026-100651 vllm before 0.29.0 Denial of Service via Decoder Prompt Length Bypass CWE-400 6.5 Medium 2026-09-26
CVE-2026-100649 vLLM before 0.29.0 Resource Limit Bypass via Sampler Subclass CWE-770 3.7 Low 2026-09-26
CVE-2026-100650 vLLM before 0.29.0 Resource Exhaustion via Unbounded Media Materialization CWE-400 6.5 Medium 2026-09-26
CVE-2026-100648 vllm before 0.29.0 Uncontrolled Resource Consumption via Audio Decoding CWE-400 5.3 Medium 2026-09-26
CVE-2026-100647 vLLM before 0.29.0 CPU Exhaustion via unbounded cache_salt CWE-20 5.3 Medium 2026-09-26
CVE-2026-94627 vLLM through 0.29.0 GPU KV Cache Leak via Mooncake Transfer ID Collision CWE-401 7.5 High 2026-09-21
CVE-2026-94626 vLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_size CWE-789 7.5 High 2026-09-21
CVE-2026-94625 vLLM through 0.29.0 Resource Exhaustion via Ownerless Mooncake Transfer Placeholders CWE-772 5.3 Medium 2026-09-21
CVE-2026-94624 vLLM through 0.29.0 Denial of Service via Unbounded P2P KV Offloading Sessions CWE-770 7.5 High 2026-09-21
CVE-2026-94623 vLLM through 0.29.0 Denial of Service via NIXL Multi-Prompt Assertion Failure CWE-617 7.5 High 2026-09-21
CVE-2026-94622 vLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer Metadata CWE-248 7.5 High 2026-09-21
CVE-2026-93989 vLLM through 0.29.0 Cross-Request Logits Corruption via bad_words CWE-129 3.1 Low 2026-09-19
CVE-2026-93841 vLLM through 0.29.0 Adjacent-Request Sampler State Corruption via Unvalidated Prompt Token IDs CWE-129 3.7 Low 2026-09-18
CVE-2026-93840 vLLM before 0.29.0 Cross-Request Logits Corruption via allowed_token_ids CWE-129 3.7 Low 2026-09-18
CVE-2026-93592 vLLM before 0.28.0 Denial of Service via negative token ID CWE-129 7.5 High 2026-09-18

All 98 known CVE vulnerabilities affecting vllm with full Chinese analysis, references, and POCs where available.