Vllm

Vllm

85 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.31%
  • Veröffentlicht 26.09.2026 13:23:21
  • Zuletzt bearbeitet 06.10.2026 19:30:25

vLLM before 0.29.0 fails to enforce decoder prompt-length validation on the disaggregated serving endpoint /inference/v1/generate. When the request contains a 'features' (multimodal) payload, vllm/entrypoints/serve/disagg/serving.py builds a multimod...

Exploit
  • EPSS 0.61%
  • Veröffentlicht 26.09.2026 13:23:20
  • Zuletzt bearbeitet 06.10.2026 19:32:45

vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls (the VLLM_MAX_AUDIO_CLIP_FILESIZE_MB compressed-audio size cap, default 25 MB, and the per-modality --limit-mm-per-prompt item li...

  • EPSS 0.31%
  • Veröffentlicht 26.09.2026 13:23:19
  • Zuletzt bearbeitet 06.10.2026 19:37:35

vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler subclass shadowing allows independent counter increments. Unauthenticated attackers can select different sampler subclasses in video ...

  • EPSS 0.33%
  • Veröffentlicht 26.09.2026 13:23:18
  • Zuletzt bearbeitet 06.10.2026 19:40:20

vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing unauthenticated clients to bypass file size restrictions. Attackers can submit oversized audio files through chat endpoints to consu...

  • EPSS 0.31%
  • Veröffentlicht 26.09.2026 13:23:18
  • Zuletzt bearbeitet 06.10.2026 19:46:06

vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-compatible and Anthropic API endpoints, which lacks maximum length validation and is processed on the single EngineCore scheduler thr...

  • EPSS 0.45%
  • Veröffentlicht 21.09.2026 22:04:16
  • Zuletzt bearbeitet 29.09.2026 12:46:29

vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Attackers can trigger GPU memory exhaustion by submitt...

  • EPSS 0.45%
  • Veröffentlicht 21.09.2026 22:04:15
  • Zuletzt bearbeitet 29.09.2026 12:46:53

vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggregate...

  • EPSS 0.3%
  • Veröffentlicht 21.09.2026 22:04:14
  • Zuletzt bearbeitet 29.09.2026 12:47:01

vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send rejected requests to exhaust sender task pools, ...

  • EPSS 0.45%
  • Veröffentlicht 21.09.2026 22:04:13
  • Zuletzt bearbeitet 29.09.2026 12:47:10

vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_...

  • EPSS 0.45%
  • Veröffentlicht 21.09.2026 22:04:12
  • Zuletzt bearbeitet 29.09.2026 12:47:21

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Att...