vLLM vulnerabilities
CVEs whose affected-version data names the vLLM package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
82 CVEsRSS
CVE-2026-56340High· 8.8vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing
vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests with mal…
GHSA-78fp-cf4h-g36pHigh· 8.8Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164
Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164
GHSA-vfm7-4h43-gp6mMedium· 4.3Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service
Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service
CVE-2026-54235Medium· 6.5vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels
vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels
CVE-2026-12491Medium· 4.8vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
CVE-2026-53923High· 7.5vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
CVE-2026-54236Medium· 5.3PoCvLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
CVE-2026-54233Medium· 6.5vLLM: OOM Denial of Service via Audio Decompression Bomb
vLLM: OOM Denial of Service via Audio Decompression Bomb
GHSA-x8xr-mj9x-6h7wMedium· 4.8Duplicate Advisory: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
Duplicate Advisory: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
CVE-2026-5497High· 7.5vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method
vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method. When processing `video/jpeg` data URLs, the method …
CVE-2026-47155Medium· 6.5vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
CVE-2026-9540Medium· 5.3vllm has Improper Resource Shutdown or Release
vllm has Improper Resource Shutdown or Release
CVE-2026-44222Medium· 6.5vLLM Vulnerable to Remote DoS via Special-Token Placeholders
vLLM Vulnerable to Remote DoS via Special-Token Placeholders
CVE-2026-7141Medium· 5.6vLLM makes Use of Uninitialized Resource
vLLM makes Use of Uninitialized Resource
CVE-2026-34756Medium· 6.5vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in the vLLM OpenAI-compatible API server. Due to the lack of an upper bound validation on the…
CVE-2026-34755Medium· 6.5vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.load_base64() method at vllm/multimodal/media/video.py splits video/jpeg data URLs by comma to extract individual JPE…
CVE-2026-34753Medium· 5.4PoCvLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `
vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `
CVE-2026-34760High· 7.1vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, Librosa defaults t…
vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, Librosa defaults to using numpy.mean for mono downmixing (to_mono), while the international standard ITU-R BS.775-4 sp…
CVE-2026-27893High· 8.8vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the…
CVE-2026-25960Medium· 5.4vLLM has SSRF Protection Bypass
vLLM has SSRF Protection Bypass
CVE-2026-22778Critical· 9.8PoCvLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a hea…
CVE-2026-24779High· 7.1vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability exists in the `MediaConnector` class within the vLLM project's multimodal feature set. …
CVE-2026-22807High· 8.8PoCvLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_…
CVE-2026-22773Medium· 6.5vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3 vision model implementation by sending a s…
CVE-2025-62372Medium· 6.5vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
CVE-2025-62164High· 8.8vLLM deserialization vulnerability leading to DoS and potential RCE
vLLM deserialization vulnerability leading to DoS and potential RCE
CVE-2025-62426Medium· 6.5vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`
vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`
CVE-2025-61620Medium· 6.5vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
CVE-2025-6242High· 7.1vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
CVE-2025-9141High· 8.8vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder