CVE-2026-73560
- EPSS 0.32%
- Veröffentlicht 17.08.2026 20:17:25
- Zuletzt bearbeitet 18.08.2026 16:18:17
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/processors/mimo_v2_omni.py passes attacker-controlled image and audio strings through _fetch_image, reque...
CVE-2026-71486
- EPSS 0.34%
- Veröffentlicht 17.08.2026 20:16:45
- Zuletzt bearbeitet 18.08.2026 13:17:29
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied GenerateResponse objects whose generate_responses, choices, token_ids,...
CVE-2026-73559
- EPSS 0.39%
- Veröffentlicht 13.08.2026 15:09:02
- Zuletzt bearbeitet 14.08.2026 17:20:33
vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in vllm/entrypoints/openai/completion/protocol.py accepts an unbounded list[str] or list[list[int]], promp...
CVE-2026-73558
- EPSS 0.26%
- Veröffentlicht 13.08.2026 15:06:06
- Zuletzt bearbeitet 13.08.2026 16:19:05
vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.cu can cause act_and_mul_kernel to consume another batched user's input, allowing a request processed ...
CVE-2026-73557
- EPSS 0.25%
- Veröffentlicht 13.08.2026 15:00:15
- Zuletzt bearbeitet 13.08.2026 18:18:18
vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds in vllm/renderers/embed_utils.py uses torch.sparse.check_sparse_tensor_invariants, whose process-global save, enable, and restore ...
CVE-2026-73556
- EPSS 0.32%
- Veröffentlicht 13.08.2026 14:56:52
- Zuletzt bearbeitet 14.08.2026 17:20:33
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer.RegexParser without compile_regex_with...
CVE-2026-73555
- EPSS 0.26%
- Veröffentlicht 13.08.2026 14:50:03
- Zuletzt bearbeitet 14.08.2026 16:17:00
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_message in vll...
CVE-2026-55514
- EPSS 0.37%
- Veröffentlicht 06.07.2026 20:07:40
- Zuletzt bearbeitet 07.07.2026 19:02:37
vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with a model using M-RoPE causes EngineCore to fail an assertion and fatally crash, shutting down the ent...
CVE-2026-55574
- EPSS 0.32%
- Veröffentlicht 06.07.2026 20:05:31
- Zuletzt bearbeitet 07.07.2026 19:03:35
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular expression string directly to the grammar compiler backends with no compi...
CVE-2026-54234
- EPSS 0.36%
- Veröffentlicht 06.07.2026 19:49:20
- Zuletzt bearbeitet 07.07.2026 19:04:17
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative decoding workload can cause the rejection sampler to produce a recovered token equal to the model vocabu...