Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

vllm-project — Vulnerabilities & Security Advisories 58

Browse all 58 CVE security advisories affecting vllm-project. AI-powered Chinese analysis, POCs, and references for each vulnerability.

vllm-project is an open-source library designed for high-throughput and memory-efficient inference of large language models, primarily serving developers who require optimized serving infrastructure for generative AI applications. Despite its utility in streamlining model deployment, the software has accumulated thirty-three recorded Common Vulnerabilities and Exposures (CVEs), indicating significant historical security debt. Analysis of these flaws reveals a prevalence of input validation errors and improper access controls, which frequently lead to remote code execution and privilege escalation scenarios. These vulnerabilities often stem from inadequate sanitization of user-supplied data within the inference pipeline, allowing attackers to manipulate model outputs or execute arbitrary commands on the host system. While no single catastrophic breach has been widely publicized, the sheer volume of disclosed issues suggests that the project has struggled with consistent security auditing during its rapid development phase. Users must apply rigorous patching and network segmentation to mitigate these risks when deploying vllm-project in production environments.

Top products by vllm-project: vllm vllm-project/vllm
CVE ID Title CVSS Severity Published
CVE-2026-73560 vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections — vllm CWE-918 6.5 Medium 2026-08-17
CVE-2026-71486 vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds — vllm CWE-400 4.3 Medium 2026-08-17
CVE-2026-73559 vLLM: Completion prompt lists fan out into unbounded engine requests — vllm CWE-400 6.5 Medium 2026-08-13
CVE-2026-73558 vLLM: Cross-User Data Leak Vulnerability — vllm CWE-190 5.3 Medium 2026-08-13
CVE-2026-73557 vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts — vllm CWE-362 6.3 Medium 2026-08-13
CVE-2026-73556 vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of CVE-2026-55574 — vllm CWE-400 5.3 Medium 2026-08-13
CVE-2026-73555 vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages — vllm CWE-209 5.3 Medium 2026-08-13
CVE-2026-55514 vLLM denial of service via prompt embeds on M-RoPE models — vllm CWE-617 - - 2026-07-06
CVE-2026-55574 vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends — vllm CWE-1333 - - 2026-07-06
CVE-2026-54234 vLLM: Remote DoS in vLLM via Invalid Recovered Token Reinjection — vllm CWE-20 7.5 High 2026-07-06
CVE-2026-55646 vLLM speech-to-text endpoints allocate full upload before enforcing the audio file-size limit — vllm CWE-400 6.5 Medium 2026-07-06
CVE-2026-47155 vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors — vllm CWE-345 6.5 Medium 2026-06-22
CVE-2026-41523 vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution — vllm CWE-94 7.5 High 2026-06-22
CVE-2026-54232 vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile — vllm CWE-427 8.8 High 2026-06-22
CVE-2026-54233 vLLM: OOM Denial of Service via Audio Decompression Bomb — vllm CWE-409 6.5 Medium 2026-06-22
CVE-2026-54236 vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router — vllm CWE-532 5.3 Medium 2026-06-22
CVE-2026-54235 vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels — vllm CWE-1287 - - 2026-06-22
CVE-2026-48746 vLLM: OpenAI auth bypass — vllm CWE-444 9.1 Critical 2026-06-22
CVE-2026-53923 vLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overflow — vllm CWE-681 - - 2026-06-22
CVE-2026-12491 Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectations — vLLM CWE-115 4.8 Medium 2026-06-17
CVE-2026-5497 Unbounded Frame Count in video/jpeg Base64 Data URL Processing Leads to OOM DoS in vllm-project/vllm — vllm-project/vllm CWE-400 - - 2026-06-11
CVE-2026-4944 Hardcoded trust_remote_code=True in vllm-project/vllm Bypasses User Security Control — vllm-project/vllm CWE-22 - - 2026-05-28
CVE-2026-9540 vllm-project vllm OpenAI-compatible Serving Path denial of service — vllm CWE-404 5.3 Medium 2026-05-26
CVE-2026-44223 vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters — vllm CWE-131 6.5 Medium 2026-05-12
CVE-2026-44222 vLLM: Remote DoS via Special-Token Placeholders — vllm CWE-129 6.5 Medium 2026-05-12
CVE-2026-34756 vLLM Affected by Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server — vllm CWE-770 6.5 Medium 2026-04-06
CVE-2026-34755 vLLM Affected by Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing — vllm CWE-770 6.5 Medium 2026-04-06
CVE-2026-34753 vLLM affected by Server-Side Request Forgery (SSRF) in `download_bytes_from_url ` — vllm CWE-918 5.4 Medium 2026-04-06
CVE-2026-34760 vLLM: Downmix Implementation Differences as Attack Vectors Against Audio AI Models — vllm CWE-20 5.9 Medium 2026-04-02
CVE-2026-27893 vLLM's hardcoded trust_remote_code=True in NemotronVL and KimiK25 bypasses user security opt-out — vllm CWE-693 8.8 High 2026-03-26

This page lists every published CVE security advisory associated with vllm-project. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.