CVE-2026-9540
- EPSS 0.43%
- Veröffentlicht 26.05.2026 10:30:12
- Zuletzt bearbeitet 26.05.2026 19:54:40
A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The ex...
CVE-2026-44223
- EPSS 0.37%
- Veröffentlicht 12.05.2026 19:58:40
- Zuletzt bearbeitet 22.06.2026 22:16:45
vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect shape after the first decode step, causing a Ru...
CVE-2026-44222
- EPSS 0.41%
- Veröffentlicht 12.05.2026 19:57:25
- Zuletzt bearbeitet 14.05.2026 15:38:19
vLLM is an inference and serving engine for large language models (LLMs). From 0.6.1 to before 0.20.0, there is a a Token Injection vulnerability in vLLM’s multimodal processing. Unauthenticated, text-only prompts that spell special tokens are interp...
CVE-2026-34756
- EPSS 0.29%
- Veröffentlicht 06.04.2026 15:40:03
- Zuletzt bearbeitet 20.04.2026 18:30:39
vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in the vLLM OpenAI-compatible API server. Due to the lack of an upper bound validation on the n parameter ...
CVE-2026-34755
- EPSS 0.28%
- Veröffentlicht 06.04.2026 15:38:53
- Zuletzt bearbeitet 20.04.2026 18:31:12
vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.load_base64() method at vllm/multimodal/media/video.py splits video/jpeg data URLs by comma to extract individual JPEG frames, but...
CVE-2026-34753
- EPSS 0.25%
- Veröffentlicht 06.04.2026 15:36:52
- Zuletzt bearbeitet 20.04.2026 18:31:56
vLLM is an inference and serving engine for large language models (LLMs). From 0.16.0 to before 0.19.0, a server-side request forgery (SSRF) vulnerability in download_bytes_from_url allows any actor who can control batch input JSON to make the vLLM b...
CVE-2026-34760
- EPSS 0.27%
- Veröffentlicht 02.04.2026 18:59:49
- Zuletzt bearbeitet 11.05.2026 13:24:40
vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, Librosa defaults to using numpy.mean for mono downmixing (to_mono), while the international standard ITU-R BS.775-4 specifies a wei...
CVE-2026-27893
- EPSS 0.75%
- Veröffentlicht 26.03.2026 23:56:53
- Zuletzt bearbeitet 30.03.2026 18:56:21
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user's expli...
CVE-2026-25960
- EPSS 0.44%
- Veröffentlicht 09.03.2026 21:16:15
- Zuletzt bearbeitet 18.03.2026 18:36:10
vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in the load_from_url_async method due to inconsistent URL parsing behavior between the validation layer...
CVE-2026-22778
- EPSS 3.28%
- Veröffentlicht 02.02.2026 23:16:06
- Zuletzt bearbeitet 23.02.2026 18:19:12
vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. Wi...