Vulnerabilities

Last updated 1 hour ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
vllm No summary available Unknown 10 days ago 3 hours ago
vllm No summary available Medium Risk 5.3 10 days ago 3 hours ago
vllm No summary available Unknown 11 days ago 3 hours ago
vllm No summary available Medium Risk 5.3 10 days ago 3 hours ago
vllm No summary available Medium Risk 4.3 9 days ago 3 hours ago
vllm vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation Medium Risk 6.5 11 days ago 11 days ago
vllm No summary available Unknown 16 days ago 12 days ago
vllm vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions Medium Risk 6.5 12 days ago 12 days ago
vllm vLLM introduced enhanced protection for CVE-2025-62164 High Risk 8.8 8 months ago 17 days ago
vllm vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds Medium Risk 4.3 24 days ago 19 days ago
vllm vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages Medium Risk 5.3 24 days ago 19 days ago
vllm vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts Medium Risk 6.0 24 days ago 19 days ago
vllm vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m Medium Risk 5.3 24 days ago 19 days ago
vllm vLLM: Cross-User Data Leak Vulnerability Medium Risk 5.3 20 days ago 19 days ago
vllm vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections Medium Risk 6.5 20 days ago 19 days ago
vllm vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections Medium Risk 6.5 19 days ago 19 days ago
vllm vLLM: Cross-User Data Leak Vulnerability Medium Risk 5.3 19 days ago 19 days ago
vllm vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds Medium Risk 4.3 19 days ago 19 days ago
vllm vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages Medium Risk 5.3 19 days ago 19 days ago
vllm vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m Medium Risk 5.3 19 days ago 19 days ago
vllm vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts Unknown 19 days ago 19 days ago
vllm vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends High Risk 7.5 2 months ago 19 days ago
vllm vLLM has Remote DoS via Invalid Recovered Token Reinjection High Risk 7.5 2 months ago 19 days ago
vllm vLLM: OOM Denial of Service via Audio Decompression Bomb Medium Risk 6.5 3 months ago 19 days ago
vllm vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations Medium Risk 4.8 3 months ago 19 days ago
vllm vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving High Risk 7.5 3 months ago 19 days ago
vllm vLLM Vulnerable to Remote DoS via Special-Token Placeholders Medium Risk 6.5 4 months ago 19 days ago
vllm vLLM makes Use of Uninitialized Resource Medium Risk 5.6 5 months ago 19 days ago
vllm vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url ` Medium Risk 5.4 5 months ago 19 days ago
vllm vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing Medium Risk 6.5 5 months ago 19 days ago
vllm vLLM deserialization vulnerability leading to DoS and potential RCE High Risk 8.8 10 months ago 19 days ago
vllm vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs Medium Risk 6.5 10 months ago 19 days ago
vllm vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors Medium Risk 6.5 3 months ago 19 days ago
vllm vLLM: Completion prompt lists fan out into unbounded engine requests Medium Risk 6.5 1 month ago 19 days ago
vllm vLLM denial of service via prompt embeds on M-RoPE models High Risk 8.0 2 months ago 19 days ago
vllm vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution High Risk 7.5 3 months ago 19 days ago
vllm vLLM: OpenAI auth bypass Critical 9.1 3 months ago 19 days ago
vllm vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router Medium Risk 5.3 3 months ago 19 days ago
vllm vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels Medium Risk 6.5 3 months ago 19 days ago
vllm vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters Medium Risk 6.5 4 months ago 19 days ago
vllm vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server Medium Risk 6.5 5 months ago 19 days ago
vllm vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out High Risk 8.8 6 months ago 19 days ago
vllm vLLM has RCE In Video Processing Critical 9.8 7 months ago 19 days ago
vllm vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions Medium Risk 6.5 8 months ago 19 days ago
vllm vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector High Risk 7.1 8 months ago 19 days ago
vllm vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs` Medium Risk 6.5 10 months ago 19 days ago
vllm vLLM is vulnerable to timing attack at bearer auth High Risk 7.5 11 months ago 19 days ago
vllm vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class High Risk 7.1 11 months ago 19 days ago
vllm vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server Medium Risk 6.5 11 months ago 19 days ago
vllm vllm API endpoints vulnerable to Denial of Service Attacks High Risk 7.5 1 year ago 19 days ago