VulnSea

vllm has 63 CVEs on record between 2024 and 2026. Cadence is steady at roughly 12 per quarter. The busiest recent month was June 2026 with 11. The median CVSS is 6.5 (medium), with 9 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-770 (7) and CWE-400 (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
—
Last 90 days
12 prev 18

Products

  • vllm 63
63
Total CVEs
9
Critical
0
CISA KEV
0
Exploited

vllm vulnerabilities

CVEs affecting vllm, newest first. Open any entry for full detail, references, and exploit status.

63 CVEsRSS

CVE-2026-27893High· 8.8
6mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the…

▾ Twilightvllm · vllmEPSS 1.8%via NVD
CVE-2026-25960Medium· 5.4
6mo ago

vLLM has SSRF Protection Bypass

vLLM has SSRF Protection Bypass

▾ Sunlitvllm · vllmEPSS 0.72%via OSV
CVE-2026-22778Critical· 9.8PoC
7mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a hea…

▾ Abyssalvllm · vllmEPSS 10%via NVD
CVE-2026-24779High· 7.1
8mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability exists in the `MediaConnector` class within the vLLM project's multimodal feature set. …

▾ Twilightvllm · vllmEPSS 0.59%via NVD
CVE-2026-22807High· 8.8PoC
8mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_…

▾ Midnightvllm · vllmEPSS 0.83%via NVD
CVE-2026-22773Medium· 6.5
8mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3 vision model implementation by sending a s…

▾ Sunlitvllm · vllmEPSS 0.45%via NVD
CVE-2025-62372Medium· 6.5
10mo ago

vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs

vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs

▾ Sunlitvllm · vllmEPSS 0.38%via OSV
CVE-2025-62164High· 8.8
10mo ago

vLLM deserialization vulnerability leading to DoS and potential RCE

vLLM deserialization vulnerability leading to DoS and potential RCE

▾ Twilightvllm · vllmEPSS 0.93%via OSV
CVE-2025-61620Medium· 6.5
11mo ago

vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server

vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server

▾ Sunlitvllm · vllmvia OSV
CVE-2025-6242High· 7.1
11mo ago

vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class

vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class

▾ Twilightvllm · vllmEPSS 0.25%via OSV
CVE-2025-9141High· 8.8
1y ago

vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

▾ Twilightvllm · vllmvia OSV
CVE-2025-48887Medium· 6.5
1y ago

vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`

vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`

▾ Sunlitvllm · vllmEPSS 0.51%via OSV
CVE-2025-46722Medium· 4.2
1y ago

vLLM has a Weakness in MultiModalHasher Image Hashing Implementation

vLLM has a Weakness in MultiModalHasher Image Hashing Implementation

▾ Sunlitvllm · vllmEPSS 0.32%via OSV
CVE-2025-48943Medium· 6.5
1y ago

vLLM allows clients to crash the openai server with invalid regex

vLLM allows clients to crash the openai server with invalid regex

▾ Sunlitvllm · vllmEPSS 0.47%via OSV
CVE-2025-48942Medium· 6.5
1y ago

vLLM DOS: Remotely kill vllm over http with invalid JSON schema

vLLM DOS: Remotely kill vllm over http with invalid JSON schema

▾ Sunlitvllm · vllmEPSS 0.54%via OSV
CVE-2025-46570Low· 2.6
1y ago

Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching

Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching

▾ Sunlitvllm · vllmEPSS 0.29%via OSV
CVE-2025-48944Medium· 6.5
1y ago

vLLM Tool Schema allows DoS via Malformed pattern and type Fields

vLLM Tool Schema allows DoS via Malformed pattern and type Fields

▾ Sunlitvllm · vllmEPSS 0.52%via OSV
CVE-2025-71379Medium· 4.3
1y ago

vLLM vulnerable to Regular Expression Denial of Service

vLLM vulnerable to Regular Expression Denial of Service

▾ Sunlitvllm · vllmEPSS 0.48%via OSV
CVE-2025-47277Critical· 9.8
1y ago

vLLM Allows Remote Code Execution via PyNcclPipe Communication Service

vLLM Allows Remote Code Execution via PyNcclPipe Communication Service

▾ Midnightvllm · vllmEPSS 0.96%via OSV
CVE-2025-30165High· 8.0
1y ago

Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration

Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration

▾ Twilightvllm · vllmEPSS 0.48%via OSV
CVE-2025-32444Critical· 10.0
1y ago

vLLM Vulnerable to Remote Code Execution via Mooncake Integration

vLLM Vulnerable to Remote Code Execution via Mooncake Integration

▾ Midnightvllm · vllmEPSS 1.8%via OSV
CVE-2025-46560Medium· 6.5
1y ago

phi4mm: Quadratic Time Complexity in Input Token Processing​ leads to denial of service

phi4mm: Quadratic Time Complexity in Input Token Processing​ leads to denial of service

▾ Sunlitvllm · vllmEPSS 0.52%via OSV
CVE-2025-30202High· 7.5
1y ago

Data exposure via ZeroMQ on multi-node vLLM deployment

Data exposure via ZeroMQ on multi-node vLLM deployment

▾ Twilightvllm · vllmEPSS 0.60%via OSV
GHSA-ggpf-24jw-3fcwCritical· 9.8
1y ago

CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0

CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0

▾ Midnightvllm · vllmvia OSV
CVE-2024-9052Critical· 9.8
1y ago

vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object

vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object

▾ Midnightvllm · vllmvia OSV
CVE-2024-9053Critical· 9.8
1y ago

vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints

vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints

▾ Midnightvllm · vllmEPSS 1.4%via OSV
CVE-2024-11041Critical· 9.8
1y ago

vLLM Deserialization of Untrusted Data vulnerability

vLLM Deserialization of Untrusted Data vulnerability

▾ Midnightvllm · vllmEPSS 1.6%via OSV
CVE-2025-29783Critical· 9.0
1y ago

vLLM Allows Remote Code Execution via Mooncake Integration

vLLM Allows Remote Code Execution via Mooncake Integration

▾ Midnightvllm · vllmEPSS 0.73%via OSV
CVE-2025-29770Medium· 6.5
1y ago

vLLM denial of service via outlines unbounded cache on disk

vLLM denial of service via outlines unbounded cache on disk

▾ Sunlitvllm · vllmEPSS 0.46%via OSV
CVE-2025-25183Low· 2.6
1y ago

vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache

vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache

▾ Sunlitvllm · vllmEPSS 0.19%via OSV
vllm vulnerabilities (CVEs) — page 2 · VulnSea