Skip to content
vLLMGHSA-pgr7-mhp5-fgjp

vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object

Critical9.8CVE-2024-9052 · Published Mar 20, 2025 · updated Aug 7, 2026

vllm-project vllm version 0.6.0 contains a vulnerability in the distributed training API. The function vllm.distributed.GroupCoordinator.recv_object() deserializes received object bytes using pickle.loads() without sanitization, leading to a remote code execution vulnerability. ### Maintainer perspective Note that vLLM does NOT use the code as described in the report on huntr. The problem only exists if you use these internal APIs in a way that exposes them to a network as described. The vllm team was not involved in the analysis of this report and the decision to assign it a CVE.

GitHub advisory

Affected versions

PackageAffectedFixed in
vllm
PyPI
<= 0.8.1No fix yet
Details and references

More vLLM advisories

All vLLM
Advisory
vLLM: code execution
Critical9.8Apr 23, 2025
vLLM vulnerable to Denial of Service by abusing xgrammar cache
Medium6.5Apr 15, 2025
vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
Critical9.8Mar 20, 2025
vLLM Deserialization of Untrusted Data vulnerability
Critical9.8Mar 20, 2025
vLLM Allows Remote Code Execution via Mooncake Integration
Critical9.0Mar 19, 2025
vLLM denial of service via outlines unbounded cache on disk
Medium6.5Mar 19, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.