vLLM Vulnerable to Remote Code Execution via Mooncake Integration
Critical10.0CVE-2025-32444 · Published Apr 29, 2025 · updated Aug 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vllm PyPI | >= 0.6.5, < 0.8.5 | 0.8.5 |
Details and references
## Impacted Deployments **Note that vLLM instances that do NOT make use of the mooncake integration are NOT vulnerable.** ## Description vLLM integration with mooncake is vaulnerable to remote code execution due to using `pickle` based serialization over unsecured ZeroMQ sockets. The vulnerable sockets were set to listen on all network interfaces, increasing the likelihood that an attacker is able to reach the vulnerable ZeroMQ sockets to carry out an attack. This is a similar to [GHSA - x3m8 - f7g5 - qhm7](https://github.com/vllm-project/vllm/security/advisories/GHSA-x3m8-f7g5-qhm7), the problem is in https://github.com/vllm-project/vllm/blob/32b14baf8a1f7195ca09484de3008063569b43c5/vllm/distributed/kv_transfer/kv_pipe/mooncake_pipe.py#L179 Here [recv_pyobj()](https://github.com/zeromq/pyzmq/blob/453f00c5645a3bea40d79f53aa8c47d85038dc2d/zmq/sugar/socket.py#L961) Contains implicit `pickle.loads()`, which leads to potential RCE.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-502
- Also known as
- CVE-2025-32444, PYSEC-2025-42
- github.com/vllm-project/vllm/security/advisories/GHSA-hj4w-hm2g-p6w5
- github.com/vllm-project/vllm/security/advisories/GHSA-x3m8-f7g5-qhm7
- nvd.nist.gov/vuln/detail/CVE-2025-32444
- github.com/vllm-project/vllm/commit/a5450f11c95847cf51a17207af9a3ca5ab569b2c
- github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-42.yaml
- github.com/vllm-project/vllm
- github.com/vllm-project/vllm/blob/32b14baf8a1f7195ca09484de3008063569b43c5/vllm/distributed/kv_transfer/kv_pipe/mooncake_pipe.py#L179
More vLLM advisories
All vLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 292025 | Data exposure via ZeroMQ on multi-node vLLM deployment CVE-2025-30202High7.5fixed in 0.8.5 | High7.5 | 0.8.5 |
| Apr 292025 | vLLM: Quadratic Time Complexity in Input Token Processing leads to denial of service CVE-2025-46560Medium6.5fixed in 0.8.5 | Medium6.5 | 0.8.5 |
| Apr 232025 | CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0 GHSA-ggpf-24jw-3fcwCritical9.8fixed in 0.8.0 | Critical9.8 | 0.8.0 |
| May 62025 | Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration CVE-2025-30165High8.0fixed in 0.10.0 | High8.0 | 0.10.0 |
| Apr 152025 | vLLM vulnerable to Denial of Service by abusing xgrammar cache GHSA-hf3c-wxg2-49q9Medium6.5fixed in 0.8.4 | Medium6.5 | 0.8.4 |
| May 202025 | vLLM Allows Remote Code Execution via PyNcclPipe Communication Service CVE-2025-47277Critical9.8fixed in 0.8.5 | Critical9.8 | 0.8.5 |