CVE-2026-5497
- EPSS 0.54%
- Veröffentlicht 11.06.2026 08:31:18
- Zuletzt bearbeitet 22.07.2026 12:18:17
vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method. When processing `video/jpeg` data URLs, the method splits the ba...
CVE-2026-4944
- EPSS 0.75%
- Veröffentlicht 28.05.2026 18:04:05
- Zuletzt bearbeitet 29.05.2026 15:39:34
vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in two model implementation files (`vllm/model_executor/models/nemotron_vl.py` and `vllm/model_executor/models/kimi_k25.py`). This byp...
CVE-2026-9540
- EPSS 0.43%
- Veröffentlicht 26.05.2026 10:30:12
- Zuletzt bearbeitet 23.07.2026 11:10:00
A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The ex...
CVE-2026-44223
- EPSS 0.37%
- Veröffentlicht 12.05.2026 19:58:40
- Zuletzt bearbeitet 22.06.2026 22:16:45
vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect shape after the first decode step, causing a Ru...
CVE-2026-44222
- EPSS 0.41%
- Veröffentlicht 12.05.2026 19:57:25
- Zuletzt bearbeitet 14.05.2026 15:38:19
vLLM is an inference and serving engine for large language models (LLMs). From 0.6.1 to before 0.20.0, there is a a Token Injection vulnerability in vLLM’s multimodal processing. Unauthenticated, text-only prompts that spell special tokens are interp...
CVE-2026-34756
- EPSS 0.35%
- Veröffentlicht 06.04.2026 15:40:03
- Zuletzt bearbeitet 20.08.2026 13:18:04
vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in the vLLM OpenAI-compatible API server. Due to the lack of an upper bound validation on the n parameter ...
CVE-2026-34755
- EPSS 0.38%
- Veröffentlicht 06.04.2026 15:38:53
- Zuletzt bearbeitet 20.08.2026 13:18:02
vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.load_base64() method at vllm/multimodal/media/video.py splits video/jpeg data URLs by comma to extract individual JPEG frames, but...
CVE-2026-34753
- EPSS 0.25%
- Veröffentlicht 06.04.2026 15:36:52
- Zuletzt bearbeitet 20.04.2026 18:31:56
vLLM is an inference and serving engine for large language models (LLMs). From 0.16.0 to before 0.19.0, a server-side request forgery (SSRF) vulnerability in download_bytes_from_url allows any actor who can control batch input JSON to make the vLLM b...
CVE-2026-34760
- EPSS 0.27%
- Veröffentlicht 02.04.2026 18:59:49
- Zuletzt bearbeitet 24.07.2026 21:10:00
vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, Librosa defaults to using numpy.mean for mono downmixing (to_mono), while the international standard ITU-R BS.775-4 specifies a wei...
CVE-2026-27893
- EPSS 1.35%
- Veröffentlicht 26.03.2026 23:56:53
- Zuletzt bearbeitet 21.07.2026 12:17:51
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user's expli...