CVE-2025-32444
- EPSS 1.67%
- Veröffentlicht 30.04.2025 00:25:00
- Zuletzt bearbeitet 28.05.2025 19:12:58
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and prior to 0.8.5, having vLLM integration with mooncake, are vulnerable to remote code execution due to using pickle based serializat...
CVE-2025-46560
- EPSS 0.49%
- Veröffentlicht 30.04.2025 00:24:53
- Zuletzt bearbeitet 28.05.2025 19:15:56
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.8.0 and prior to 0.8.5 are affected by a critical performance vulnerability in the input preprocessing logic of the multimodal tokenizer. T...
CVE-2025-30202
- EPSS 0.57%
- Veröffentlicht 30.04.2025 00:24:45
- Zuletzt bearbeitet 14.05.2025 19:59:42
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.5.2 and prior to 0.8.5 are vulnerable to denial of service and data exposure via ZeroMQ on multi-node vLLM deployment. In a multi-node vLLM...
CVE-2024-9053
- EPSS 1.36%
- Veröffentlicht 20.03.2025 10:09:33
- Zuletzt bearbeitet 15.10.2025 13:15:57
vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core functionality run_server_loop() calls the function _make_handler_coro(), which directly uses cloudpickle.loads() on received messa...