VDB
Sign up
HIGH7.5

PYSEC-2026-2024

vLLM denial of service vulnerability

Quick fix

PYSEC-2026-2024 — vllm: upgrade to the fixed version with the command below.

pip install --upgrade 'vllm>=0.5.5'

Details

A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/vllm
Introduced in: 0Fixed in: 0.5.5
Fixpip install --upgrade 'vllm>=0.5.5'

References