MEDIUM 5.3
GHSA-98f3-hwg4-4rf7
vllm has Improper Resource Shutdown or Release
상세
A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
PyPI / vllm
최초 영향 버전:
0 No fixed version published yet for vllm (pip). Pin to a known-safe version or switch to an alternative.
참고
- https://nvd.nist.gov/vuln/detail/CVE-2026-9540 [ADVISORY]
- https://github.com/vllm-project/vllm/issues/37343 [WEB]
- https://github.com/vllm-project/vllm/pull/37594 [WEB]
- https://github.com/vllm-project/vllm [PACKAGE]
- https://ingero.io/debugging-vllm-latency-minimax-ollama-mcp [WEB]
- https://vuldb.com/submit/814645 [WEB]
- https://vuldb.com/vuln/365601 [WEB]
- https://vuldb.com/vuln/365601/cti [WEB]