CVE-2025-48956High· 7.5▾ TwilightA flaw was found in vLLM. A denial of service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large X-Forwarded-For header to an HTTP endpoint. This results in server memory exhaustion, potential…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.5%
0.5% → 0.6%
Last analysed / modified upstream
A flaw was found in vLLM. A denial of service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large X-Forwarded-For header to an HTTP endpoint. This results in server memory exhaustion, potentially leading to a crash or unresponsiveness. The attack does not require authentication, making it exploitable by any remote user.
vllm: HTTP header size limit not enforced allows Denial of Service from Unauthenticated requests — rated Important by Red Hat. Released 2025-08-26, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
For more information visit https://access.redhat.com/errata/RHSA-2025:19427 https://access.redhat.com/errata/RHSA-2025:19427 For more information visit https://access.redhat.com/errata/RHSA-2025:19429 https://access.redhat.com/errata/RHSA-2025:19429 For more information visit https://access.redhat.com/errata/RHSA-2025:19424 https://access.redhat.com/errata/RHSA-2025:19424
Workarounds / mitigations:
Affected packages:
vllm >= 0.1.0, < 0.10.1.1Patched in:
vllm 0.10.1.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62426Medium· 6.5vllm: vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs` (CVE-2025-624…
CVE-2026-44223Medium· 6.5vLLM is an inference and serving engine for large language models (LLMs)
CVE-2026-33022Medium· 6.5github.com/tektoncd/pipeline: Tekton Pipelines: Denial of Service via long resolver names (CVE-2026-33022)
CVE-2026-90678High· 7.5An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5
CVE-2026-89613Medium· 5.5kernel: ntfs: reject invalid empty mapping pairs (CVE-2026-89613)
CVE-2026-89480High· 7.0kernel: nvme-tcp: reject a read that transferred too few bytes (CVE-2026-89480)