All 98 CVE vulnerabilities found in vllm, with AI-generated Chinese analysis, references, and POCs.
This page aggregates known security vulnerabilities affecting the vLLM software product, a high-throughput inference engine for large language models. It collects advisories related to specific weakness types, covering the period from the project's initial release through the most recent updates. Readers can use this resource to track the vendor's published advisories, understand common vulnerability classes within the codebase, and review the product's historical security record without hunting through individual commit messages or release notes. The collection focuses on flaws in input validation, resource management, and deserialization, reflecting the primary attack surfaces identified by the community. This summary provides a consolidated view of past issues to support risk assessment and patching strategies.
Vendor: vllm-project
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-30165 | Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration CWE-502 | 8.0 | High | 2025-05-06 |
| CVE-2025-32444 | vLLM Vulnerable to Remote Code Execution via Mooncake Integration CWE-502 | 10.0 | Critical | 2025-04-30 |
| CVE-2025-46560 | vLLM phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service CWE-1333 | 6.5 | Medium | 2025-04-30 |
| CVE-2025-30202 | Data exposure via ZeroMQ on multi-node vLLM deployment CWE-770 | 7.5 | High | 2025-04-30 |
| CVE-2025-29783 | vLLM Allows Remote Code Execution via Mooncake Integration CWE-502 | 9.1 | Critical | 2025-03-19 |
| CVE-2025-29770 | vLLM denial of service via outlines unbounded cache on disk CWE-770 | 6.5 | Medium | 2025-03-19 |
| CVE-2025-25183 | vLLM using built-in hash() from Python 3.12 leads to predictable hash collisions in vLLM prefix cache CWE-354 | 2.6 | Low | 2025-02-07 |
| CVE-2025-24357 | vLLM allows a malicious model RCE by torch.load in hf_model_weights_iterator CWE-502 | 7.5 | High | 2025-01-27 |
All 98 known CVE vulnerabilities affecting vllm with full Chinese analysis, references, and POCs where available.