Skip to content
vLLMGHSA-9hcf-v7m4-6m2j

vLLM allows clients to crash the openai server with invalid regex

Medium6.5CVE-2025-48943 · Published May 28, 2025 · updated Aug 7, 2026

### Impact A denial of service bug caused the vLLM server to crash if an invalid regex was provided while using structured output. This vulnerability is similar to [GHSA-6qc9-v4r8-22xg](https://github.com/vllm-project/vllm/security/advisories/GHSA-6qc9-v4r8-22xg), but for regex instead of a JSON schema. Issue with more details: https://github.com/vllm-project/vllm/issues/17313 ### Patches * https://github.com/vllm-project/vllm/pull/17623

GitHub advisory

Affected versions

PackageAffectedFixed in
vllm
PyPI
>= 0.8.0, < 0.9.00.9.0
Details and references

More vLLM advisories

All vLLM
Advisory
vLLM Tool Schema allows DoS via Malformed pattern and type Fields
Medium6.5May 28, 2025
vLLM DOS: Remotely kill vllm over http with invalid JSON schema
Medium6.5May 28, 2025
vLLM has a Weakness in MultiModalHasher Image Hashing Implementation
Medium4.2May 28, 2025
Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
Low2.6May 28, 2025
vLLM vulnerable to Regular Expression Denial of Service
Medium4.3May 28, 2025
vLLM: denial of service
Medium6.5May 28, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.