VulnSea

vLLM vulnerabilities

CVEs whose affected-version data names the vLLM package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

80 CVEsRSS

CVE-2025-48943Medium· 6.5
1y ago

vLLM allows clients to crash the openai server with invalid regex

vLLM allows clients to crash the openai server with invalid regex

▾ Sunlitvllm · vllmEPSS 0.47%via OSV
CVE-2025-48942Medium· 6.5
1y ago

vLLM DOS: Remotely kill vllm over http with invalid JSON schema

vLLM DOS: Remotely kill vllm over http with invalid JSON schema

▾ Sunlitvllm · vllmEPSS 0.54%via OSV
CVE-2025-46570Low· 2.6
1y ago

Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching

Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching

▾ Sunlitvllm · vllmEPSS 0.29%via OSV
CVE-2025-48944Medium· 6.5
1y ago

vLLM Tool Schema allows DoS via Malformed pattern and type Fields

vLLM Tool Schema allows DoS via Malformed pattern and type Fields

▾ Sunlitvllm · vllmEPSS 0.52%via OSV
CVE-2025-71379Medium· 4.3
1y ago

vLLM vulnerable to Regular Expression Denial of Service

vLLM vulnerable to Regular Expression Denial of Service

▾ Sunlitvllm · vllmEPSS 0.48%via OSV
CVE-2025-47277Critical· 9.8
1y ago

vLLM Allows Remote Code Execution via PyNcclPipe Communication Service

vLLM Allows Remote Code Execution via PyNcclPipe Communication Service

▾ Midnightvllm · vllmEPSS 0.96%via OSV
CVE-2025-30165High· 8.0
1y ago

Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration

Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration

▾ Twilightvllm · vllmEPSS 0.48%via OSV
CVE-2025-32444Critical· 10.0
1y ago

vLLM Vulnerable to Remote Code Execution via Mooncake Integration

vLLM Vulnerable to Remote Code Execution via Mooncake Integration

▾ Midnightvllm · vllmEPSS 1.7%via OSV
CVE-2025-46560Medium· 6.5
1y ago

phi4mm: Quadratic Time Complexity in Input Token Processing​ leads to denial of service

phi4mm: Quadratic Time Complexity in Input Token Processing​ leads to denial of service

▾ Sunlitvllm · vllmEPSS 0.50%via OSV
CVE-2025-30202High· 7.5
1y ago

Data exposure via ZeroMQ on multi-node vLLM deployment

Data exposure via ZeroMQ on multi-node vLLM deployment

▾ Twilightvllm · vllmEPSS 0.57%via OSV
GHSA-ggpf-24jw-3fcwCritical· 9.8
1y ago

CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0

CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0

▾ Midnightvllm · vllmvia OSV
CVE-2024-9052Critical· 9.8
1y ago

vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object

vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object

▾ Midnightvllm · vllmvia OSV
CVE-2024-9053Critical· 9.8
1y ago

vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints

vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints

▾ Midnightvllm · vllmEPSS 1.4%via OSV
CVE-2024-11041Critical· 9.8
1y ago

vLLM Deserialization of Untrusted Data vulnerability

vLLM Deserialization of Untrusted Data vulnerability

▾ Midnightvllm · vllmEPSS 1.6%via OSV
CVE-2025-29783Critical· 9.0
1y ago

vLLM Allows Remote Code Execution via Mooncake Integration

vLLM Allows Remote Code Execution via Mooncake Integration

▾ Midnightvllm · vllmEPSS 0.73%via OSV
CVE-2025-29770Medium· 6.5
1y ago

vLLM denial of service via outlines unbounded cache on disk

vLLM denial of service via outlines unbounded cache on disk

▾ Sunlitvllm · vllmEPSS 0.46%via OSV
CVE-2025-25183Low· 2.6
1y ago

vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache

vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache

▾ Sunlitvllm · vllmEPSS 0.19%via OSV
CVE-2025-24357High· 7.5
1y ago

vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator

vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator

▾ Twilightvllm · vllmEPSS 0.70%via OSV
CVE-2024-8939Medium· 6.2
2y ago

vLLM Denial of Service via the best_of parameter

vLLM Denial of Service via the best_of parameter

▾ Sunlitvllm · vllmEPSS 0.23%via OSV
CVE-2024-8768High· 7.5
2y ago

vLLM denial of service vulnerability

vLLM denial of service vulnerability

▾ Twilightvllm · vllmEPSS 0.68%via OSV
vLLM vulnerabilities (CVEs) — page 3 · VulnSea