CVEs we hold for Vllm-project
Records whose assigning authority named Vllm-project as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-93841vLLM through 0.29.0 Adjacent-Request Sampler State Corruption via Unvalidated Prompt Token IDsvllm-project vllm
CVE-2026-93840vLLM before 0.29.0 Cross-Request Logits Corruption via allowed_token_idsvllm-project vllm
CVE-2026-92220vllm-project vLLM MoRIIO Acknowledgement moriio_connector.py MoRIIOWrapper._handle_release_message resource consumptionvllm-project vLLM
CVE-2026-90878vllm-project vLLM Jinja Template Rendering completions resource consumptionvllm-project vLLM
CVE-2026-90553vLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processorvllm-project vLLM
CVE-2026-73560vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass…vllm-project vllm
CVE-2026-73557vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt partsvllm-project vllm
CVE-2026-73556vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of…vllm-project vllm
CVE-2026-73555vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messagesvllm-project vllm
CVE-2026-71486vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output boundsvllm-project vllm
CVE-2026-69147vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservationvllm-project vllm
CVE-2026-57173vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completionsvllm-project vllm
CVE-2026-55646vLLM speech-to-text endpoints allocate full upload before enforcing the audio file-size limitvllm-project vllm
CVE-2026-55574vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backendsvllm-project vllm
CVE-2026-5497Unbounded Frame Count in video/jpeg Base64 Data URL Processing Leads to OOM DoS in vllm-project/vllmvllm-project/vllm
CVE-2026-54236vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic routervllm-project vllm
CVE-2026-54235vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernelsvllm-project vllm
CVE-2026-53923vLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overflowvllm-project vllm
CVE-2026-4944Hardcoded trust_remote_code=True in vllm-project/vllm Bypasses User Security Controlvllm-project/vllm
CVE-2026-47155vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processorsvllm-project vllm
CVE-2026-44223vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parametersvllm-project vllm
CVE-2026-41523vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Executionvllm-project vllm
CVE-2026-34760vLLM: Downmix Implementation Differences as Attack Vectors Against Audio AI Modelsvllm-project vllm
CVE-2026-34756vLLM Affected by Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Servervllm-project vllm
CVE-2026-34755vLLM Affected by Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processingvllm-project vllm
CVE-2026-34753vLLM affected by Server-Side Request Forgery (SSRF) in `download_bytes_from_url `vllm-project vllm
CVE-2026-27893vLLM's hardcoded trust_remote_code=True in NemotronVL and KimiK25 bypasses user security opt-outvllm-project vllm
CVE-2026-24779vLLM vulnerable to Server-Side Request Forgery (SSRF) in `MediaConnector`vllm-project vllm
CVE-2026-22807vLLM affected by RCE via auto_map dynamic module loading during model initializationvllm-project vllm
CVE-2026-22773vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensionsvllm-project vllm
CVE-2026-12491Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and…vllm-project vLLM; Red Hat AI Inference Server…
CVE-2025-66448vLLM vulnerable to remote code execution via transformers_utils/get_configvllm-project vllm
CVE-2025-62426vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`vllm-project vllm
CVE-2025-62372vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputsvllm-project vllm
CVE-2025-48887vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in…vllm-project vllm
CVE-2025-47277vLLM Allows Remote Code Execution via PyNcclPipe Communication Servicevllm-project vllm
CVE-2025-46570vLLM’s Chunk-Based Prefix Caching Vulnerable to Potential Timing Side-Channelvllm-project vllm
CVE-2025-46560vLLM phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of servicevllm-project vllm
CVE-2025-30165Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configurationvllm-project vllm
CVE-2025-25183vLLM using built-in hash() from Python 3.12 leads to predictable hash collisions in vLLM prefix cachevllm-project vllm
CVE-2025-24357vLLM allows a malicious model RCE by torch.load in hf_model_weights_iteratorvllm-project vllm
72 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.