Vllm-project

Vllm

94 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.45%
  • Veröffentlicht 21.09.2026 22:04:16
  • Zuletzt bearbeitet 29.09.2026 12:46:29

vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Attackers can trigger GPU memory exhaustion by submitt...

  • EPSS 0.45%
  • Veröffentlicht 21.09.2026 22:04:15
  • Zuletzt bearbeitet 29.09.2026 12:46:53

vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggregate...

  • EPSS 0.3%
  • Veröffentlicht 21.09.2026 22:04:14
  • Zuletzt bearbeitet 29.09.2026 12:47:01

vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send rejected requests to exhaust sender task pools, ...

  • EPSS 0.45%
  • Veröffentlicht 21.09.2026 22:04:13
  • Zuletzt bearbeitet 29.09.2026 12:47:10

vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_...

  • EPSS 0.45%
  • Veröffentlicht 21.09.2026 22:04:12
  • Zuletzt bearbeitet 29.09.2026 12:47:21

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Att...

  • EPSS 0.45%
  • Veröffentlicht 21.09.2026 22:04:10
  • Zuletzt bearbeitet 29.09.2026 12:47:29

vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with incomplete kv_transfer_params dictionary entries to trigge...

  • EPSS 0.2%
  • Veröffentlicht 19.09.2026 22:58:10
  • Zuletzt bearbeitet 28.09.2026 18:38:31

vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token indices that corrupt logits memory of concurrent re...

  • EPSS 0.24%
  • Veröffentlicht 18.09.2026 19:06:06
  • Zuletzt bearbeitet 28.09.2026 18:35:40

vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size. Attackers can submit multimodal audio reque...

  • EPSS 0.25%
  • Veröffentlicht 18.09.2026 19:06:06
  • Zuletzt bearbeitet 28.09.2026 18:36:00

vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). Attackers can supply token IDs above the output vocabulary that pass validation, causing Log...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 18.09.2026 13:20:05
  • Zuletzt bearbeitet 28.09.2026 18:37:06

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID...