vllm has 63 CVEs on record between 2024 and 2026. Cadence is steady at roughly 12 per quarter. The busiest recent month was June 2026 with 11. The median CVSS is 6.5 (medium), with 9 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-770 (7) and CWE-400 (5).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 12 prev 18
Weakness classes
Products
- vllm 63
63
Total CVEs
9
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-22778Critical· 9.8vLLM is an inference and serving engine for large language models (LLMs)68CVE-2026-48746Critical· 9.1vLLM is an inference and serving engine for large language models (LLMs)62CVE-2026-22807High· 8.8vLLM is an inference and serving engine for large language models (LLMs)61CVE-2025-32444Critical· 10.0vLLM Vulnerable to Remote Code Execution via Mooncake Integration55CVE-2025-47277Critical· 9.8vLLM Allows Remote Code Execution via PyNcclPipe Communication Service54
vllm vulnerabilities
CVEs affecting vllm, newest first. Open any entry for full detail, references, and exploit status.
63 CVEsRSS
CVE-2025-24357High· 7.5vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator
vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator
▾ Twilightvllm · vllmEPSS 0.70%via OSV
CVE-2024-8939Medium· 6.2vLLM Denial of Service via the best_of parameter
vLLM Denial of Service via the best_of parameter
▾ Sunlitvllm · vllmEPSS 0.23%via OSV
CVE-2024-8768High· 7.5vLLM denial of service vulnerability
vLLM denial of service vulnerability
▾ Twilightvllm · vllmEPSS 0.68%via OSV