vllm vulnerabilities
CVEs whose affected-version data names the vllm package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
80 CVEsRSS
CVE-2025-48943Medium· 6.5vLLM allows clients to crash the openai server with invalid regex
vLLM allows clients to crash the openai server with invalid regex
CVE-2025-48942Medium· 6.5vLLM DOS: Remotely kill vllm over http with invalid JSON schema
vLLM DOS: Remotely kill vllm over http with invalid JSON schema
CVE-2025-46570Low· 2.6Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
CVE-2025-48944Medium· 6.5vLLM Tool Schema allows DoS via Malformed pattern and type Fields
vLLM Tool Schema allows DoS via Malformed pattern and type Fields
CVE-2025-71379Medium· 4.3vLLM vulnerable to Regular Expression Denial of Service
vLLM vulnerable to Regular Expression Denial of Service
CVE-2025-47277Critical· 9.8vLLM Allows Remote Code Execution via PyNcclPipe Communication Service
vLLM Allows Remote Code Execution via PyNcclPipe Communication Service
CVE-2025-30165High· 8.0Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
CVE-2025-32444Critical· 10.0vLLM Vulnerable to Remote Code Execution via Mooncake Integration
vLLM Vulnerable to Remote Code Execution via Mooncake Integration
CVE-2025-46560Medium· 6.5phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
CVE-2025-30202High· 7.5Data exposure via ZeroMQ on multi-node vLLM deployment
Data exposure via ZeroMQ on multi-node vLLM deployment
GHSA-ggpf-24jw-3fcwCritical· 9.8CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
CVE-2024-9052Critical· 9.8vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
CVE-2024-9053Critical· 9.8vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
CVE-2024-11041Critical· 9.8vLLM Deserialization of Untrusted Data vulnerability
vLLM Deserialization of Untrusted Data vulnerability
CVE-2025-29783Critical· 9.0vLLM Allows Remote Code Execution via Mooncake Integration
vLLM Allows Remote Code Execution via Mooncake Integration
CVE-2025-29770Medium· 6.5vLLM denial of service via outlines unbounded cache on disk
vLLM denial of service via outlines unbounded cache on disk
CVE-2025-25183Low· 2.6vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache
vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache
CVE-2025-24357High· 7.5vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator
vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator
CVE-2024-8939Medium· 6.2vLLM Denial of Service via the best_of parameter
vLLM Denial of Service via the best_of parameter
CVE-2024-8768High· 7.5vLLM denial of service vulnerability
vLLM denial of service vulnerability