Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

vllm — Vulnerabilities & Security Advisories 98

All 98 CVE vulnerabilities found in vllm, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting the vLLM software product, a high-throughput inference engine for large language models. It collects advisories related to specific weakness types, covering the period from the project's initial release through the most recent updates. Readers can use this resource to track the vendor's published advisories, understand common vulnerability classes within the codebase, and review the product's historical security record without hunting through individual commit messages or release notes. The collection focuses on flaws in input validation, resource management, and deserialization, reflecting the primary attack surfaces identified by the community. This summary provides a consolidated view of past issues to support risk assessment and patching strategies.

Vendor: vllm-project

CVE ID Title CVSS Severity Published
CVE-2026-56340 vLLM - Denial of Service via Unvalidated Multimodal Embeddings CWE-20 8.8 High 2026-06-20
CVE-2025-71379 vllm - Regular Expression Denial of Service in Multiple Components CWE-1333 4.3 Medium 2026-06-20
CVE-2026-12491 Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectations CWE-115 4.8 Medium 2026-06-17
CVE-2026-9540 vllm-project vllm OpenAI-compatible Serving Path denial of service CWE-404 5.3 Medium 2026-05-26
CVE-2026-44223 vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters CWE-131 6.5 Medium 2026-05-12
CVE-2026-44222 vLLM: Remote DoS via Special-Token Placeholders CWE-129 6.5 Medium 2026-05-12
CVE-2026-7141 vLLM KV Block kv_cache_interface.py has_mamba_layers uninitialized resource CWE-908 5.6 Medium 2026-04-27
CVE-2026-34756 vLLM Affected by Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server CWE-770 6.5 Medium 2026-04-06
CVE-2026-34755 vLLM Affected by Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing CWE-770 6.5 Medium 2026-04-06
CVE-2026-34753 vLLM affected by Server-Side Request Forgery (SSRF) in `download_bytes_from_url ` CWE-918 5.4 Medium 2026-04-06
CVE-2026-34760 vLLM: Downmix Implementation Differences as Attack Vectors Against Audio AI Models CWE-20 5.9 Medium 2026-04-02
CVE-2026-27893 vLLM's hardcoded trust_remote_code=True in NemotronVL and KimiK25 bypasses user security opt-out CWE-693 8.8 High 2026-03-26
CVE-2026-25960 SSRF Protection Bypass in vLLM CWE-918 7.1 High 2026-03-09
CVE-2026-22778 vLLM leaks a heap address when PIL throws an error CWE-532 9.8 Critical 2026-02-02
CVE-2026-24779 vLLM vulnerable to Server-Side Request Forgery (SSRF) in `MediaConnector` CWE-918 7.1 High 2026-01-27
CVE-2026-22807 vLLM affected by RCE via auto_map dynamic module loading during model initialization CWE-94 8.8 High 2026-01-21
CVE-2026-22773 vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions CWE-770 6.5 Medium 2026-01-10
CVE-2025-66448 vLLM vulnerable to remote code execution via transformers_utils/get_config CWE-94 7.1 High 2025-12-01
CVE-2025-62372 vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs CWE-129 7.5 - 2025-11-21
CVE-2025-62426 vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs` CWE-770 6.5 Medium 2025-11-21
CVE-2025-62164 VLLM deserialization vulnerability leading to DoS and potential RCE CWE-20 8.8 High 2025-11-21
CVE-2025-59425 vLLM vulnerable to timing attack at bearer auth CWE-385 7.5 High 2025-10-07
CVE-2025-48956 vLLM API endpoints vulnerable to Denial of Service Attacks CWE-400 7.5 High 2025-08-21
CVE-2025-48944 vLLM Tool Schema allows DoS via Malformed pattern and type Fields CWE-20 6.5 Medium 2025-05-30
CVE-2025-48943 vLLM allows clients to crash the openai server with invalid regex CWE-248 6.5 Medium 2025-05-30
CVE-2025-48942 vLLM DOS: Remotely kill vllm over http with invalid JSON schema CWE-248 6.5 Medium 2025-05-30
CVE-2025-48887 vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py` CWE-1333 6.5 Medium 2025-05-30
CVE-2025-46722 vLLM has a Weakness in MultiModalHasher Image Hashing Implementation CWE-1288 4.2 Medium 2025-05-29
CVE-2025-46570 vLLM’s Chunk-Based Prefix Caching Vulnerable to Potential Timing Side-Channel CWE-208 2.6 Low 2025-05-29
CVE-2025-47277 vLLM Allows Remote Code Execution via PyNcclPipe Communication Service CWE-502 9.8 Critical 2025-05-20

All 98 known CVE vulnerabilities affecting vllm with full Chinese analysis, references, and POCs where available.