Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

vllm — Vulnerabilities & Security Advisories 98

All 98 CVE vulnerabilities found in vllm, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting the vLLM software product, a high-throughput inference engine for large language models. It collects advisories related to specific weakness types, covering the period from the project's initial release through the most recent updates. Readers can use this resource to track the vendor's published advisories, understand common vulnerability classes within the codebase, and review the product's historical security record without hunting through individual commit messages or release notes. The collection focuses on flaws in input validation, resource management, and deserialization, reflecting the primary attack surfaces identified by the community. This summary provides a consolidated view of past issues to support risk assessment and patching strategies.

Vendor: vllm-project

CVE ID Title CVSS Severity Published
CVE-2026-93436 vLLM through 0.29.0 Memory Exhaustion via Rejected Requests CWE-401 7.5 High 2026-09-17
CVE-2026-69147 vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation CWE-400 6.5 Medium 2026-09-16
CVE-2026-57173 vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions CWE-770 6.5 Medium 2026-09-16
CVE-2026-92365 vllm-project vllm thinking_budget_state.py algorithmic complexity CWE-407 4.3 Medium 2026-09-16
CVE-2026-92220 vllm-project vLLM MoRIIO Acknowledgement moriio_connector.py MoRIIOWrapper._handle_release_message resource consumption CWE-400 5.3 Medium 2026-09-16
CVE-2026-90878 vllm-project vLLM Jinja Template Rendering completions resource consumption CWE-400 4.3 Medium 2026-09-15
CVE-2026-90713 vllm-project vLLM tiktoken vocab File mod.rs new denial of service CWE-404 3.3 Low 2026-09-14
CVE-2026-90554 vLLM before 0.28.0 Denial of Service via audio extraction CWE-400 6.2 Medium 2026-09-12
CVE-2026-90555 vLLM before 0.28.0 Denial of Service via Audio Header CWE-409 6.5 Medium 2026-09-12
CVE-2026-90553 vLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processor CWE-94 7.8 High 2026-09-12
CVE-2026-78684 vLLM before 0.27.0 Denial of Service via DeepStream Backend CWE-400 5.3 Medium 2026-08-25
CVE-2026-73560 vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections CWE-918 6.5 Medium 2026-08-17
CVE-2026-71486 vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds CWE-400 4.3 Medium 2026-08-17
CVE-2026-73559 vLLM: Completion prompt lists fan out into unbounded engine requests CWE-400 6.5 Medium 2026-08-13
CVE-2026-73558 vLLM: Cross-User Data Leak Vulnerability CWE-190 5.3 Medium 2026-08-13
CVE-2026-73557 vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts CWE-362 6.3 Medium 2026-08-13
CVE-2026-73556 vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of CVE-2026-55574 CWE-400 5.3 Medium 2026-08-13
CVE-2026-73555 vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages CWE-209 5.3 Medium 2026-08-13
CVE-2026-55514 vLLM denial of service via prompt embeds on M-RoPE models CWE-617 - - 2026-07-06
CVE-2026-55574 vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends CWE-1333 - - 2026-07-06
CVE-2026-54234 vLLM: Remote DoS in vLLM via Invalid Recovered Token Reinjection CWE-20 7.5 High 2026-07-06
CVE-2026-55646 vLLM speech-to-text endpoints allocate full upload before enforcing the audio file-size limit CWE-400 6.5 Medium 2026-07-06
CVE-2026-47155 vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors CWE-345 6.5 Medium 2026-06-22
CVE-2026-41523 vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution CWE-94 7.5 High 2026-06-22
CVE-2026-54232 vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile CWE-427 8.8 High 2026-06-22
CVE-2026-54233 vLLM: OOM Denial of Service via Audio Decompression Bomb CWE-409 6.5 Medium 2026-06-22
CVE-2026-54236 vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router CWE-532 5.3 Medium 2026-06-22
CVE-2026-54235 vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels CWE-1287 - - 2026-06-22
CVE-2026-48746 vLLM: OpenAI auth bypass CWE-444 9.1 Critical 2026-06-22
CVE-2026-53923 vLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overflow CWE-681 - - 2026-06-22

All 98 known CVE vulnerabilities affecting vllm with full Chinese analysis, references, and POCs where available.