CVE-2025-59425
- EPSS 0.53%
- Veröffentlicht 07.10.2025 14:15:38
- Zuletzt bearbeitet 16.10.2025 18:02:09
vLLM is an inference and serving engine for large language models (LLMs). Before version 0.11.0rc2, the API key support in vLLM performs validation using a method that was vulnerable to a timing attack. API key validation uses a string comparison tha...
CVE-2025-48956
- EPSS 0.56%
- Veröffentlicht 21.08.2025 14:41:03
- Zuletzt bearbeitet 09.10.2025 18:04:53
vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.10.1.1, a Denial of Service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large header to an HTTP endpoint....
CVE-2025-48944
- EPSS 0.48%
- Veröffentlicht 30.05.2025 18:38:45
- Zuletzt bearbeitet 01.07.2025 20:42:13
vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, the vLLM backend used with the /v1/chat/completions OpenAPI endpoint fails to validate unexpected or malformed input in the "pattern...
CVE-2025-48943
- EPSS 0.44%
- Veröffentlicht 30.05.2025 18:36:01
- Zuletzt bearbeitet 02.06.2025 17:32:17
vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) that causes the vLLM server to crash if an invalid regex was provided while using structured output. Th...
CVE-2025-48942
- EPSS 0.5%
- Veröffentlicht 30.05.2025 18:33:40
- Zuletzt bearbeitet 02.06.2025 17:32:17
vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, hitting the /v1/completions API with a invalid json_schema as a Guided Param kills the vllm server. This vulnerability is similar ...
CVE-2025-48887
- EPSS 0.47%
- Veröffentlicht 30.05.2025 17:36:16
- Zuletzt bearbeitet 19.06.2025 00:55:27
vLLM, an inference and serving engine for large language models (LLMs), has a Regular Expression Denial of Service (ReDoS) vulnerability in the file `vllm/entrypoints/openai/tool_parsers/pythonic_tool_parser.py` of versions 0.6.4 up to but excluding ...
CVE-2025-46722
- EPSS 0.29%
- Veröffentlicht 29.05.2025 16:36:12
- Zuletzt bearbeitet 30.05.2025 16:31:03
vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before 0.9.0, in the file vllm/multimodal/hasher.py, the MultiModalHasher class has a security and data integrity issue in its image hashing ...
CVE-2025-46570
- EPSS 0.27%
- Veröffentlicht 29.05.2025 16:32:42
- Zuletzt bearbeitet 30.05.2025 16:31:03
vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is processed, if the PageAttention mechanism finds a matching prefix chunk, the prefill process speeds up, which is reflected in the T...
CVE-2025-47277
- EPSS 0.95%
- Veröffentlicht 20.05.2025 17:32:27
- Zuletzt bearbeitet 13.08.2025 16:35:57
vLLM, an inference and serving engine for large language models (LLMs), has an issue in versions 0.6.5 through 0.8.4 that ONLY impacts environments using the `PyNcclPipe` KV cache transfer integration with the V0 engine. No other configurations are a...
- EPSS 0.54%
- Veröffentlicht 06.05.2025 16:53:52
- Zuletzt bearbeitet 31.07.2025 18:05:30
vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, vLLM uses ZeroMQ for some multi-node communication purposes. The secondary vLLM hosts open a `SUB` ZeroMQ socket and connect to an...