vllm has 63 CVEs on record between 2024 and 2026. Cadence is steady at roughly 12 per quarter. The busiest recent month was June 2026 with 11. The median CVSS is 6.5 (medium), with 9 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-770 (7) and CWE-400 (5).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 12 prev 18
Weakness classes
Products
- vllm 63
Worst active — by depth score
CVE-2026-22778Critical· 9.8vLLM is an inference and serving engine for large language models (LLMs)68CVE-2026-48746Critical· 9.1vLLM is an inference and serving engine for large language models (LLMs)62CVE-2026-22807High· 8.8vLLM is an inference and serving engine for large language models (LLMs)61CVE-2025-32444Critical· 10.0vLLM Vulnerable to Remote Code Execution via Mooncake Integration55CVE-2025-47277Critical· 9.8vLLM Allows Remote Code Execution via PyNcclPipe Communication Service54
vllm vulnerabilities
CVEs affecting vllm, newest first. Open any entry for full detail, references, and exploit status.
63 CVEsRSS
CVE-2026-27893High· 8.8vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the…
CVE-2026-25960Medium· 5.4vLLM has SSRF Protection Bypass
vLLM has SSRF Protection Bypass
CVE-2026-22778Critical· 9.8PoCvLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a hea…
CVE-2026-24779High· 7.1vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability exists in the `MediaConnector` class within the vLLM project's multimodal feature set. …
CVE-2026-22807High· 8.8PoCvLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_…
CVE-2026-22773Medium· 6.5vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3 vision model implementation by sending a s…
CVE-2025-62372Medium· 6.5vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
CVE-2025-62164High· 8.8vLLM deserialization vulnerability leading to DoS and potential RCE
vLLM deserialization vulnerability leading to DoS and potential RCE
CVE-2025-61620Medium· 6.5vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
CVE-2025-6242High· 7.1vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
CVE-2025-9141High· 8.8vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
CVE-2025-48887Medium· 6.5vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`
vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`
CVE-2025-46722Medium· 4.2vLLM has a Weakness in MultiModalHasher Image Hashing Implementation
vLLM has a Weakness in MultiModalHasher Image Hashing Implementation
CVE-2025-48943Medium· 6.5vLLM allows clients to crash the openai server with invalid regex
vLLM allows clients to crash the openai server with invalid regex
CVE-2025-48942Medium· 6.5vLLM DOS: Remotely kill vllm over http with invalid JSON schema
vLLM DOS: Remotely kill vllm over http with invalid JSON schema
CVE-2025-46570Low· 2.6Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
CVE-2025-48944Medium· 6.5vLLM Tool Schema allows DoS via Malformed pattern and type Fields
vLLM Tool Schema allows DoS via Malformed pattern and type Fields
CVE-2025-71379Medium· 4.3vLLM vulnerable to Regular Expression Denial of Service
vLLM vulnerable to Regular Expression Denial of Service
CVE-2025-47277Critical· 9.8vLLM Allows Remote Code Execution via PyNcclPipe Communication Service
vLLM Allows Remote Code Execution via PyNcclPipe Communication Service
CVE-2025-30165High· 8.0Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
CVE-2025-32444Critical· 10.0vLLM Vulnerable to Remote Code Execution via Mooncake Integration
vLLM Vulnerable to Remote Code Execution via Mooncake Integration
CVE-2025-46560Medium· 6.5phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
CVE-2025-30202High· 7.5Data exposure via ZeroMQ on multi-node vLLM deployment
Data exposure via ZeroMQ on multi-node vLLM deployment
GHSA-ggpf-24jw-3fcwCritical· 9.8CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
CVE-2024-9052Critical· 9.8vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
CVE-2024-9053Critical· 9.8vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
CVE-2024-11041Critical· 9.8vLLM Deserialization of Untrusted Data vulnerability
vLLM Deserialization of Untrusted Data vulnerability
CVE-2025-29783Critical· 9.0vLLM Allows Remote Code Execution via Mooncake Integration
vLLM Allows Remote Code Execution via Mooncake Integration
CVE-2025-29770Medium· 6.5vLLM denial of service via outlines unbounded cache on disk
vLLM denial of service via outlines unbounded cache on disk
CVE-2025-25183Low· 2.6vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache
vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache