Vulnerabilities
CVE-2026-47155
vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
CVE-2025-48887
CVE-2025-48887
CVE-2025-48887
vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`
CVE-2025-32444
vLLM Vulnerable to Remote Code Execution via Mooncake Integration
CVE-2025-32444
CVE-2025-32444
CVE-2024-9053
CVE-2024-9053
CVE-2026-22773
vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions
CVE-2025-29770
vLLM denial of service via outlines unbounded cache on disk
CVE-2024-9053
vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
CVE-2026-44223
vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters
CVE-2026-34755
vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing
CVE-2026-7141
vLLM makes Use of Uninitialized Resource
CVE-2026-44222
vLLM Vulnerable to Remote DoS via Special-Token Placeholders
CVE-2026-44223
CVE-2026-44223
CVE-2026-34755
CVE-2026-34755
CVE-2026-22773
CVE-2026-22773
CVE-2025-29770
CVE-2025-29770
CVE-2026-34756
vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server
CVE-2026-34753
vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `
CVE-2026-27893
vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out
CVE-2026-22778
vLLM has RCE In Video Processing
CVE-2026-24779
vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector
CVE-2026-25960
vLLM has SSRF Protection Bypass
CVE-2025-47277
vLLM Allows Remote Code Execution via PyNcclPipe Communication Service
CVE-2025-48956
vllm API endpoints vulnerable to Denial of Service Attacks
CVE-2025-30202
Data exposure via ZeroMQ on multi-node vLLM deployment
CVE-2025-46560
phi4mm: Quadratic Time Complexity in Input Token Processing​ leads to denial of service
CVE-2026-22807
vLLM affected by RCE via auto_map dynamic module loading during model initialization
CVE-2025-24357
vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator
CVE-2024-8768
vLLM denial of service vulnerability
CVE-2025-6242
vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
CVE-2024-8939
vLLM Denial of Service via the best_of parameter
CVE-2024-9052
vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
CVE-2025-25183
vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache
CVE-2025-9141
vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
CVE-2025-46570
Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
CVE-2025-30165
Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
GHSA-j828-28rj-hfhp
vLLM vulnerable to Regular Expression Denial of Service
CVE-2025-62426
vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`
CVE-2024-11041
vLLM Deserialization of Untrusted Data vulnerability
CVE-2025-62164
vLLM deserialization vulnerability leading to DoS and potential RCE
CVE-2025-46722
vLLM has a Weakness in MultiModalHasher Image Hashing Implementation
CVE-2025-48943
vLLM allows clients to crash the openai server with invalid regex
CVE-2025-59425
vLLM is vulnerable to timing attack at bearer auth
CVE-2025-48944
vLLM Tool Schema allows DoS via Malformed pattern and type Fields
CVE-2025-29783
vLLM Allows Remote Code Execution via Mooncake Integration
GHSA-ggpf-24jw-3fcw
CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
CVE-2025-62372
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
CVE-2025-61620
vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
CVE-2025-48942
vLLM DOS: Remotely kill vllm over http with invalid JSON schema
GHSA-mcmc-2m55-j8jj
vLLM introduced enhanced protection for CVE-2025-62164
CVE-2025-66448
vLLM vulnerable to remote code execution via transformers_utils/get_config
CVE-2025-29783
CVE-2025-29783
CVE-2025-25183
CVE-2025-25183
CVE-2025-24357
CVE-2025-24357
CVE-2025-46570
CVE-2025-46570
CVE-2025-48943
CVE-2025-48943
CVE-2025-48942
CVE-2025-48942
CVE-2025-46722
CVE-2025-46722
GHSA-hf3c-wxg2-49q9
vLLM vulnerable to Denial of Service by abusing xgrammar cache
Ready to move
Start Securing
Free, no credit card | First findings in minutes