Skip to content
vLLMGHSA-98f3-hwg4-4rf7

vllm has Improper Resource Shutdown or Release

Medium5.3CVE-2026-9540 · Published May 26, 2026 · updated Jul 13, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
vllm
PyPI
<= 0.19.0No fix yet
Details and references

A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-404
Also known as
CVE-2026-9540, PYSEC-2026-3407

More vLLM advisories

All vLLM
DateAdvisory
Jun 10vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
CVE-2026-47155Medium6.5fixed in 0.22.0
Jun 11vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method
CVE-2026-5497High7.5fixed in 0.19.0
May 6vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters
CVE-2026-44223Medium6.5fixed in 0.20.0
May 5vLLM Vulnerable to Remote DoS via Special-Token Placeholders
CVE-2026-44222Medium6.5fixed in 0.20.0
Jun 16vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
CVE-2026-41523High7.5fixed in 0.22.0
Jun 16vLLM: OpenAI auth bypass
CVE-2026-48746Critical9.1fixed in 0.22.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.