100 Total advisories
100 Vulnerabilities
0 Malware

Dependency scanning

Check whether vllm is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 6.5
PyPI

CVE-2026-69147

vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation

UNKNOWN
PyPI

CVE-2026-90553

CVE-2026-90553

MEDIUM 6.5
PyPI

CVE-2026-57173

vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions

HIGH 8.8
PyPI

GHSA-78fp-cf4h-g36p

Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164

HIGH 8.8
PyPI

CVE-2026-56340

vLLM introduced enhanced protection for CVE-2025-62164

MEDIUM 4.3
PyPI

GHSA-vfm7-4h43-gp6m

Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service

MEDIUM 4.3
PyPI

CVE-2026-71486

vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

MEDIUM 5.3
PyPI

CVE-2026-73555

vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

UNKNOWN
PyPI

CVE-2026-73557

vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

MEDIUM 5.3
PyPI

CVE-2026-73556

vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m

MEDIUM 5.3
PyPI

CVE-2026-73558

vLLM: Cross-User Data Leak Vulnerability

MEDIUM 6.5
PyPI

CVE-2026-73560

vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

MEDIUM 4.3
PyPI

CVE-2026-71486

vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

MEDIUM 5.3
PyPI

CVE-2026-73558

vLLM: Cross-User Data Leak Vulnerability

MEDIUM 6.5
PyPI

CVE-2026-73560

vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

MEDIUM 5.3
PyPI

CVE-2026-73555

vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

MEDIUM 5.3
PyPI

CVE-2026-73556

vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m

UNKNOWN
PyPI

CVE-2026-73557

vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

HIGH 7.5
PyPI

CVE-2026-55574

vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends

HIGH 7.5
PyPI

CVE-2026-54234

vLLM has Remote DoS via Invalid Recovered Token Reinjection

MEDIUM 4.8
PyPI

CVE-2026-12491

vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

MEDIUM 6.5
PyPI

CVE-2026-54233

vLLM: OOM Denial of Service via Audio Decompression Bomb

HIGH 7.5
PyPI

CVE-2026-53923

vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving

MEDIUM 6.5
PyPI

CVE-2026-44222

vLLM Vulnerable to Remote DoS via Special-Token Placeholders

MEDIUM 5.6
PyPI

CVE-2026-7141

vLLM makes Use of Uninitialized Resource

MEDIUM 6.5
PyPI

CVE-2026-34755

vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing

MEDIUM 5.4
PyPI

CVE-2026-34753

vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `

HIGH 8.8
PyPI

CVE-2025-62164

vLLM deserialization vulnerability leading to DoS and potential RCE

MEDIUM 6.5
PyPI

CVE-2025-62372

vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs

MEDIUM 6.5
PyPI

CVE-2026-47155

vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors

MEDIUM 6.5
PyPI

CVE-2026-73559

vLLM: Completion prompt lists fan out into unbounded engine requests

UNKNOWN
PyPI

CVE-2026-55514

vLLM denial of service via prompt embeds on M-RoPE models

HIGH 7.5
PyPI

CVE-2026-41523

vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution

MEDIUM 5.3
PyPI

CVE-2026-54236

vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router

CRITICAL 9.1
PyPI

CVE-2026-48746

vLLM: OpenAI auth bypass

MEDIUM 6.5
PyPI

CVE-2026-54235

vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels

MEDIUM 6.5
PyPI

CVE-2026-44223

vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters

MEDIUM 6.5
PyPI

CVE-2026-34756

vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server

HIGH 8.8
PyPI

CVE-2026-27893

vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out

CRITICAL 9.8
PyPI

CVE-2026-22778

vLLM has RCE In Video Processing

HIGH 7.1
PyPI

CVE-2026-24779

vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector

MEDIUM 6.5
PyPI

CVE-2026-22773

vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions

MEDIUM 6.5
PyPI

CVE-2025-62426

vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`

HIGH 7.5
PyPI

CVE-2025-59425

vLLM is vulnerable to timing attack at bearer auth

MEDIUM 6.5
PyPI

CVE-2025-61620

vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server

HIGH 7.1
PyPI

CVE-2025-6242

vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class

HIGH 7.5
PyPI

CVE-2025-48956

vllm API endpoints vulnerable to Denial of Service Attacks

HIGH 8.8
PyPI

CVE-2025-9141

vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

HIGH 8.8
PyPI

CVE-2026-22807

vLLM affected by RCE via auto_map dynamic module loading during model initialization

MEDIUM 6.5
PyPI

CVE-2026-73559

vLLM: Completion prompt lists fan out into unbounded engine requests

HIGH 7.5
PyPI

CVE-2026-5497

CVE-2026-5497

HIGH 7.5
PyPI

CVE-2026-5497

vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method

CRITICAL 9.8
PyPI

CVE-2024-11041

vLLM Deserialization of Untrusted Data vulnerability

LOW 2.6
PyPI

CVE-2025-25183

vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache

HIGH 7.5
PyPI

CVE-2025-30202

Data exposure via ZeroMQ on multi-node vLLM deployment

CRITICAL 9.8
PyPI

CVE-2024-9053

vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints

CRITICAL 9.8
PyPI

GHSA-ggpf-24jw-3fcw

CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0

MEDIUM 6.5
PyPI

CVE-2025-29770

vLLM denial of service via outlines unbounded cache on disk

HIGH 8.0
PyPI

CVE-2025-30165

Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration

HIGH 7.5
PyPI

CVE-2025-24357

vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator

HIGH 7.5
PyPI

CVE-2024-8768

vLLM denial of service vulnerability

MEDIUM 4.3
PyPI

CVE-2025-71379

vLLM vulnerable to Regular Expression Denial of Service

MEDIUM 6.2
PyPI

CVE-2024-8939

vLLM Denial of Service via the best_of parameter

CRITICAL 9.8
PyPI

CVE-2024-9052

vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object

MEDIUM 6.5
PyPI

CVE-2025-48944

vLLM Tool Schema allows DoS via Malformed pattern and type Fields

MEDIUM 6.5
PyPI

CVE-2025-46560

vLLM: Quadratic Time Complexity in Input Token Processing​ leads to denial of service

CRITICAL 9.8
PyPI

CVE-2025-47277

vLLM Allows Remote Code Execution via PyNcclPipe Communication Service

LOW 2.6
PyPI

CVE-2025-46570

Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching

MEDIUM 6.5
PyPI

CVE-2025-48943

vLLM allows clients to crash the openai server with invalid regex

MEDIUM 6.5
PyPI

CVE-2025-48887

vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`

MEDIUM 4.2
PyPI

CVE-2025-46722

vLLM has a Weakness in MultiModalHasher Image Hashing Implementation

MEDIUM 6.5
PyPI

CVE-2025-48942

vLLM DOS: Remotely kill vllm over http with invalid JSON schema

CRITICAL 10.0
PyPI

CVE-2025-32444

vLLM Vulnerable to Remote Code Execution via Mooncake Integration

CRITICAL 9.0
PyPI

CVE-2025-29783

vLLM Allows Remote Code Execution via Mooncake Integration

HIGH 7.5
PyPI

CVE-2026-54234

vLLM has Remote DoS via Invalid Recovered Token Reinjection

MEDIUM 6.5
PyPI

CVE-2026-55646

vLLM: Speech-to-text upload size limit is enforced after full UploadFile read

MEDIUM 5.9
PyPI

CVE-2026-34760

vLLM: Processing differential in multi-channel audio downmixing enables hidden-input/moderation bypass for audio models

HIGH 7.1
PyPI

CVE-2025-66448

vLLM vulnerable to remote code execution via transformers_utils/get_config

MEDIUM 5.4
PyPI

CVE-2026-25960

vLLM has SSRF Protection Bypass

UNKNOWN
PyPI

CVE-2026-7141

CVE-2026-7141

MEDIUM 5.3
PyPI

CVE-2026-9540

vllm has Improper Resource Shutdown or Release

MEDIUM 5.3
PyPI

CVE-2026-9540

vllm has Improper Resource Shutdown or Release

MEDIUM 4.8
PyPI

CVE-2026-12491

vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

MEDIUM 6.5
PyPI

CVE-2026-54233

vLLM: OOM Denial of Service via Audio Decompression Bomb

UNKNOWN
PyPI

CVE-2026-54235

vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels

UNKNOWN
PyPI

CVE-2026-53923

vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving

MEDIUM 5.4
PyPI

CVE-2026-25960

vLLM has SSRF Protection Bypass

MEDIUM 5.4
PyPI

CVE-2026-34753

vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `

MEDIUM 6.5
PyPI

CVE-2026-44222

vLLM Vulnerable to Remote DoS via Special-Token Placeholders

UNKNOWN
PyPI

CVE-2026-54236

vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router

MEDIUM 6.5
PyPI

CVE-2026-55646

CVE-2026-55646

HIGH 7.5
PyPI

CVE-2026-55574

CVE-2026-55574

MEDIUM 6.5
PyPI

CVE-2026-55514

CVE-2026-55514

HIGH 8.8
PyPI

CVE-2026-27893

CVE-2026-27893

MEDIUM 6.5
PyPI

CVE-2026-47155

CVE-2026-47155

HIGH 7.1
PyPI

CVE-2026-34760

CVE-2026-34760

HIGH 7.5
PyPI

CVE-2026-41523

CVE-2026-41523

MEDIUM 6.5
PyPI

CVE-2026-34756

CVE-2026-34756

MEDIUM 6.5
PyPI

CVE-2025-46560

phi4mm: Quadratic Time Complexity in Input Token Processing​ leads to denial of service

HIGH 7.5
PyPI

CVE-2025-59425

vLLM is vulnerable to timing attack at bearer auth

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes