vLLM affected by RCE via auto_map dynamic module loading during model initialization
Modified: 9/10/2026
package
pkg:pypi/vllm
vLLM affected by RCE via auto_map dynamic module loading during model initialization
Modified: 9/10/2026
vLLM denial of service via prompt embeds on M-RoPE models
Modified: 9/10/2026
vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
Modified: 9/10/2026
vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server
Modified: 9/10/2026
vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
Modified: 9/10/2026
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
Modified: 9/10/2026
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
Modified: 9/10/2026
Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
Modified: 8/7/2026
vLLM has RCE In Video Processing
Modified: 9/10/2026
vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
Modified: 9/10/2026
vLLM Deserialization of Untrusted Data vulnerability
Modified: 8/7/2026
vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`
Modified: 9/10/2026
vLLM: Processing differential in multi-channel audio downmixing enables hidden-input/moderation bypass for audio models
Modified: 7/17/2026
vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
Modified: 9/10/2026
vLLM: OOM Denial of Service via Audio Decompression Bomb
Modified: 9/10/2026
vLLM DOS: Remotely kill vllm over http with invalid JSON schema
Modified: 8/7/2026
vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out
Modified: 9/10/2026
vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
Modified: 9/10/2026
vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels
Modified: 9/10/2026
vLLM: Cross-User Data Leak Vulnerability
Modified: 9/10/2026
vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters
Modified: 9/10/2026
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
Modified: 9/10/2026
vLLM: Completion prompt lists fan out into unbounded engine requests
Modified: 9/10/2026
vLLM vulnerable to remote code execution via transformers_utils/get_config
Modified: 7/17/2026
vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
Modified: 9/10/2026
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
Modified: 9/17/2026
vLLM has Remote DoS via Invalid Recovered Token Reinjection
Modified: 9/10/2026
vLLM: OpenAI auth bypass
Modified: 9/10/2026
vllm has Improper Resource Shutdown or Release
Modified: 7/13/2026
Data exposure via ZeroMQ on multi-node vLLM deployment
Modified: 8/7/2026
vLLM allows clients to crash the openai server with invalid regex
Modified: 8/7/2026
Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
Modified: 8/7/2026
vLLM has a Weakness in MultiModalHasher Image Hashing Implementation
Modified: 8/7/2026
vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
Modified: 8/7/2026
CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
Modified: 8/7/2026
vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions
Modified: 9/10/2026
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
Modified: 9/16/2026
vLLM vulnerable to Denial of Service by abusing xgrammar cache
Modified: 4/15/2025
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
Modified: 9/10/2026
vLLM Vulnerable to Remote Code Execution via Mooncake Integration
Modified: 8/7/2026
vLLM Allows Remote Code Execution via PyNcclPipe Communication Service
Modified: 8/7/2026
vLLM Vulnerable to Remote DoS via Special-Token Placeholders
Modified: 9/10/2026
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
Modified: 9/10/2026
vLLM vulnerable to Regular Expression Denial of Service
Modified: 8/7/2026
vLLM introduced enhanced protection for CVE-2025-62164
Modified: 9/11/2026
vLLM denial of service via outlines unbounded cache on disk
Modified: 8/7/2026
vLLM deserialization vulnerability leading to DoS and potential RCE
Modified: 9/10/2026
vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `
Modified: 9/10/2026
vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
Modified: 8/7/2026
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
Modified: 9/10/2026
vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing
Modified: 9/10/2026
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
Modified: 9/10/2026
vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
Modified: 9/10/2026
vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector
Modified: 9/10/2026
vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator
Modified: 8/7/2026
vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache
Modified: 8/7/2026
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
Modified: 9/10/2026
vllm API endpoints vulnerable to Denial of Service Attacks
Modified: 9/10/2026
vLLM has SSRF Protection Bypass
Modified: 7/17/2026
vLLM: Speech-to-text upload size limit is enforced after full UploadFile read
Modified: 7/17/2026
vLLM: Quadratic Time Complexity in Input Token Processing leads to denial of service
Modified: 8/7/2026
vLLM Tool Schema allows DoS via Malformed pattern and type Fields
Modified: 8/7/2026
vLLM denial of service vulnerability
Modified: 8/7/2026
vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`
Modified: 8/7/2026
vLLM Denial of Service via the best_of parameter
Modified: 8/7/2026
vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method
Modified: 8/18/2026
vLLM is vulnerable to timing attack at bearer auth
Modified: 9/10/2026
vLLM makes Use of Uninitialized Resource
Modified: 9/10/2026
vLLM Allows Remote Code Execution via Mooncake Integration
Modified: 8/7/2026
Modified: 6/10/2026
Modified: 5/20/2026
Modified: 6/10/2026
Modified: 5/29/2025
Modified: 6/10/2026
Modified: 6/26/2025
Modified: 6/26/2025
Modified: 6/26/2025
Modified: 6/27/2025
Modified: 7/1/2025
Modified: 7/1/2025
Modified: 5/20/2026
Modified: 5/20/2026
Modified: 5/20/2026
vLLM affected by RCE via auto_map dynamic module loading during model initialization
Modified: 7/7/2026
vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
Modified: 7/7/2026
vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`
Modified: 7/7/2026
vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
Modified: 7/7/2026
vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
Modified: 7/7/2026
vLLM vulnerable to remote code execution via transformers_utils/get_config
Modified: 7/7/2026
Data exposure via ZeroMQ on multi-node vLLM deployment
Modified: 7/7/2026
Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
Modified: 7/7/2026
vLLM deserialization vulnerability leading to DoS and potential RCE
Modified: 7/7/2026
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
Modified: 7/7/2026
vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector
Modified: 7/7/2026
vllm API endpoints vulnerable to Denial of Service Attacks
Modified: 7/7/2026
phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
Modified: 7/7/2026
vLLM Tool Schema allows DoS via Malformed pattern and type Fields
Modified: 7/7/2026
vLLM denial of service vulnerability
Modified: 7/7/2026
vLLM Denial of Service via the best_of parameter
Modified: 7/7/2026
vLLM is vulnerable to timing attack at bearer auth
Modified: 7/7/2026