vLLMGHSA-98f3-hwg4-4rf7
vllm has Improper Resource Shutdown or Release
Medium5.3CVE-2026-9540 · Published May 26, 2026 · updated Jul 13, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vllm PyPI | <= 0.19.0 | No fix yet |
Details and references
A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-404
- Also known as
- CVE-2026-9540, PYSEC-2026-3407
More vLLM advisories
All vLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 10 | vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors CVE-2026-47155Medium6.5fixed in 0.22.0 | Medium6.5 | 0.22.0 |
| Jun 11 | vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method CVE-2026-5497High7.5fixed in 0.19.0 | High7.5 | 0.19.0 |
| May 6 | vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters CVE-2026-44223Medium6.5fixed in 0.20.0 | Medium6.5 | 0.20.0 |
| May 5 | vLLM Vulnerable to Remote DoS via Special-Token Placeholders CVE-2026-44222Medium6.5fixed in 0.20.0 | Medium6.5 | 0.20.0 |
| Jun 16 | vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution CVE-2026-41523High7.5fixed in 0.22.0 | High7.5 | 0.22.0 |
| Jun 16 | vLLM: OpenAI auth bypass CVE-2026-48746Critical9.1fixed in 0.22.0 | Critical9.1 | 0.22.0 |