Vllm-project

Vllm

53 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 17.08.2026 20:17:25
  • Zuletzt bearbeitet 18.08.2026 16:18:17

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/processors/mimo_v2_omni.py passes attacker-controlled image and audio strings through _fetch_image, reque...

  • EPSS 0.34%
  • Veröffentlicht 17.08.2026 20:16:45
  • Zuletzt bearbeitet 18.08.2026 13:17:29

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied GenerateResponse objects whose generate_responses, choices, token_ids,...

  • EPSS 0.39%
  • Veröffentlicht 13.08.2026 15:09:02
  • Zuletzt bearbeitet 14.08.2026 17:20:33

vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in vllm/entrypoints/openai/completion/protocol.py accepts an unbounded list[str] or list[list[int]], promp...

  • EPSS 0.26%
  • Veröffentlicht 13.08.2026 15:06:06
  • Zuletzt bearbeitet 13.08.2026 16:19:05

vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.cu can cause act_and_mul_kernel to consume another batched user's input, allowing a request processed ...

  • EPSS 0.25%
  • Veröffentlicht 13.08.2026 15:00:15
  • Zuletzt bearbeitet 13.08.2026 18:18:18

vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds in vllm/renderers/embed_utils.py uses torch.sparse.check_sparse_tensor_invariants, whose process-global save, enable, and restore ...

  • EPSS 0.32%
  • Veröffentlicht 13.08.2026 14:56:52
  • Zuletzt bearbeitet 14.08.2026 17:20:33

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer.RegexParser without compile_regex_with...

  • EPSS 0.26%
  • Veröffentlicht 13.08.2026 14:50:03
  • Zuletzt bearbeitet 14.08.2026 16:17:00

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_message in vll...

  • EPSS 0.37%
  • Veröffentlicht 06.07.2026 20:07:40
  • Zuletzt bearbeitet 07.07.2026 19:02:37

vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with a model using M-RoPE causes EngineCore to fail an assertion and fatally crash, shutting down the ent...

  • EPSS 0.32%
  • Veröffentlicht 06.07.2026 20:05:31
  • Zuletzt bearbeitet 07.07.2026 19:03:35

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular expression string directly to the grammar compiler backends with no compi...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 06.07.2026 19:49:20
  • Zuletzt bearbeitet 07.07.2026 19:04:17

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative decoding workload can cause the rejection sampler to produce a recovered token equal to the model vocabu...