VulnSea

vLLM vulnerabilities

CVEs whose affected-version data names the vLLM package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

82 CVEsRSS

CVE-2026-56340High· 8.8
3mo ago

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests with mal…

Twilightvllm · vllmEPSS 0.64%via NVD
GHSA-78fp-cf4h-g36pHigh· 8.8
3mo ago

Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164

Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164

Twilightvllm · vllmvia GHSA
GHSA-vfm7-4h43-gp6mMedium· 4.3
3mo ago

Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service

Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service

Sunlitvllm · vllmvia GHSA
CVE-2026-54235Medium· 6.5
3mo ago

vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels

vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels

Sunlitvllm · vllmEPSS 0.45%via OSV
CVE-2026-12491Medium· 4.8
3mo ago

vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

Sunlitvllm · vllmEPSS 0.24%via OSV
CVE-2026-53923High· 7.5
3mo ago

vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving

vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving

Twilightvllm · vllmEPSS 0.48%via OSV
CVE-2026-54236Medium· 5.3PoC
3mo ago

vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router

vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router

Twilightvllm · vllmEPSS 0.93%via OSV
CVE-2026-54233Medium· 6.5
3mo ago

vLLM: OOM Denial of Service via Audio Decompression Bomb

vLLM: OOM Denial of Service via Audio Decompression Bomb

Sunlitvllm · vllmEPSS 0.42%via OSV
GHSA-x8xr-mj9x-6h7wMedium· 4.8
3mo ago

Duplicate Advisory: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

Duplicate Advisory: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

Sunlitvllm · vllmvia GHSA
CVE-2026-5497High· 7.5
3mo ago

vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method

vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method. When processing `video/jpeg` data URLs, the method …

Twilightvllm · vllmEPSS 0.54%via NVD
CVE-2026-47155Medium· 6.5
3mo ago

vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors

vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors

Sunlitvllm · vllmEPSS 0.25%via OSV
CVE-2026-9540Medium· 5.3
3mo ago

vllm has Improper Resource Shutdown or Release

vllm has Improper Resource Shutdown or Release

Sunlitvllm · vllmEPSS 0.43%via OSV
CVE-2026-44222Medium· 6.5
4mo ago

vLLM Vulnerable to Remote DoS via Special-Token Placeholders

vLLM Vulnerable to Remote DoS via Special-Token Placeholders

Sunlitvllm · vllmEPSS 0.41%via OSV
CVE-2026-7141Medium· 5.6
4mo ago

vLLM makes Use of Uninitialized Resource

vLLM makes Use of Uninitialized Resource

Sunlitvllm · vllmEPSS 0.29%via OSV
CVE-2026-34756Medium· 6.5
5mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in the vLLM OpenAI-compatible API server. Due to the lack of an upper bound validation on the…

Sunlitvllm · vllmEPSS 0.42%via NVD
CVE-2026-34755Medium· 6.5
5mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.load_base64() method at vllm/multimodal/media/video.py splits video/jpeg data URLs by comma to extract individual JPE…

Sunlitvllm · vllmEPSS 0.46%via NVD
CVE-2026-34753Medium· 5.4PoC
5mo ago

vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `

vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `

Twilightvllm · vllmEPSS 0.25%via OSV
CVE-2026-34760High· 7.1
5mo ago

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, Librosa defaults t…

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, Librosa defaults to using numpy.mean for mono downmixing (to_mono), while the international standard ITU-R BS.775-4 sp…

Twilightvllm · vllmEPSS 0.27%via OSV
CVE-2026-27893High· 8.8
5mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the…

Twilightvllm · vllmEPSS 1.3%via NVD
CVE-2026-25960Medium· 5.4
6mo ago

vLLM has SSRF Protection Bypass

vLLM has SSRF Protection Bypass

Sunlitvllm · vllmEPSS 0.54%via OSV
CVE-2026-22778Critical· 9.8PoC
7mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a hea…

Abyssalvllm · vllmEPSS 3.8%via NVD
CVE-2026-24779High· 7.1
7mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability exists in the `MediaConnector` class within the vLLM project's multimodal feature set. …

Twilightvllm · vllmEPSS 0.55%via NVD
CVE-2026-22807High· 8.8PoC
8mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_…

Midnightvllm · vllmEPSS 0.83%via NVD
CVE-2026-22773Medium· 6.5
8mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3 vision model implementation by sending a s…

Sunlitvllm · vllmEPSS 0.45%via NVD
CVE-2025-62372Medium· 6.5
10mo ago

vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs

vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs

Sunlitvllm · vllmEPSS 0.38%via OSV
CVE-2025-62164High· 8.8
10mo ago

vLLM deserialization vulnerability leading to DoS and potential RCE

vLLM deserialization vulnerability leading to DoS and potential RCE

Twilightvllm · vllmEPSS 0.89%via OSV
CVE-2025-62426Medium· 6.5
10mo ago

vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`

vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`

Sunlitvllm · vllmEPSS 0.37%via OSV
CVE-2025-61620Medium· 6.5
11mo ago

vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server

vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server

Sunlitvllm · vllmvia OSV
CVE-2025-6242High· 7.1
11mo ago

vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class

vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class

Twilightvllm · vllmEPSS 0.25%via OSV
CVE-2025-9141High· 8.8
1y ago

vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

Twilightvllm · vllmvia OSV
vLLM vulnerabilities (CVEs) — page 2 · VulnSea