Vulnerabilities
Last updated 53 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
No summary available | Unknown | 10 days ago | 2 hours ago |
|
|
No summary available | Medium Risk 5.3 | 10 days ago | 2 hours ago |
|
|
No summary available | Unknown | 11 days ago | 2 hours ago |
|
|
No summary available | Medium Risk 5.3 | 10 days ago | 2 hours ago |
|
|
No summary available | Medium Risk 4.3 | 9 days ago | 2 hours ago |
|
|
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation | Medium Risk 6.5 | 11 days ago | 11 days ago |
|
|
No summary available | Unknown | 16 days ago | 12 days ago |
|
|
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions | Medium Risk 6.5 | 12 days ago | 12 days ago |
|
|
vLLM introduced enhanced protection for CVE-2025-62164 | High Risk 8.8 | 8 months ago | 17 days ago |
|
|
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds | Medium Risk 4.3 | 24 days ago | 18 days ago |
|
|
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages | Medium Risk 5.3 | 24 days ago | 18 days ago |
|
|
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts | Medium Risk 6.0 | 24 days ago | 18 days ago |
|
|
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m | Medium Risk 5.3 | 24 days ago | 18 days ago |
|
|
vLLM: Cross-User Data Leak Vulnerability | Medium Risk 5.3 | 20 days ago | 18 days ago |
|
|
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections | Medium Risk 6.5 | 20 days ago | 18 days ago |
|
|
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections | Medium Risk 6.5 | 19 days ago | 18 days ago |
|
|
vLLM: Cross-User Data Leak Vulnerability | Medium Risk 5.3 | 19 days ago | 18 days ago |
|
|
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds | Medium Risk 4.3 | 19 days ago | 18 days ago |
|
|
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages | Medium Risk 5.3 | 19 days ago | 18 days ago |
|
|
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m | Medium Risk 5.3 | 19 days ago | 18 days ago |
|
|
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts | Unknown | 19 days ago | 18 days ago |
|
|
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends | High Risk 7.5 | 2 months ago | 19 days ago |
|
|
vLLM has Remote DoS via Invalid Recovered Token Reinjection | High Risk 7.5 | 2 months ago | 19 days ago |
|
|
vLLM: OOM Denial of Service via Audio Decompression Bomb | Medium Risk 6.5 | 3 months ago | 19 days ago |
|
|
vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations | Medium Risk 4.8 | 3 months ago | 19 days ago |
|
|
vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving | High Risk 7.5 | 3 months ago | 19 days ago |
|
|
vLLM Vulnerable to Remote DoS via Special-Token Placeholders | Medium Risk 6.5 | 4 months ago | 19 days ago |
|
|
vLLM makes Use of Uninitialized Resource | Medium Risk 5.6 | 5 months ago | 19 days ago |
|
|
vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url ` | Medium Risk 5.4 | 5 months ago | 19 days ago |
|
|
vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing | Medium Risk 6.5 | 5 months ago | 19 days ago |
|
|
vLLM deserialization vulnerability leading to DoS and potential RCE | High Risk 8.8 | 10 months ago | 19 days ago |
|
|
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs | Medium Risk 6.5 | 10 months ago | 19 days ago |
|
|
vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors | Medium Risk 6.5 | 3 months ago | 19 days ago |
|
|
vLLM: Completion prompt lists fan out into unbounded engine requests | Medium Risk 6.5 | 1 month ago | 19 days ago |
|
|
vLLM denial of service via prompt embeds on M-RoPE models | High Risk 8.0 | 2 months ago | 19 days ago |
|
|
vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution | High Risk 7.5 | 3 months ago | 19 days ago |
|
|
vLLM: OpenAI auth bypass | Critical 9.1 | 3 months ago | 19 days ago |
|
|
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router | Medium Risk 5.3 | 3 months ago | 19 days ago |
|
|
vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels | Medium Risk 6.5 | 3 months ago | 19 days ago |
|
|
vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters | Medium Risk 6.5 | 4 months ago | 19 days ago |
|
|
vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server | Medium Risk 6.5 | 5 months ago | 19 days ago |
|
|
vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out | High Risk 8.8 | 6 months ago | 19 days ago |
|
|
vLLM has RCE In Video Processing | Critical 9.8 | 7 months ago | 19 days ago |
|
|
vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions | Medium Risk 6.5 | 8 months ago | 19 days ago |
|
|
vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector | High Risk 7.1 | 8 months ago | 19 days ago |
|
|
vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs` | Medium Risk 6.5 | 10 months ago | 19 days ago |
|
|
vLLM is vulnerable to timing attack at bearer auth | High Risk 7.5 | 11 months ago | 19 days ago |
|
|
vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class | High Risk 7.1 | 11 months ago | 19 days ago |
|
|
vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server | Medium Risk 6.5 | 11 months ago | 19 days ago |
|
|
vllm API endpoints vulnerable to Denial of Service Attacks | High Risk 7.5 | 1 year ago | 19 days ago |
Page 1