Skip to content
vLLMGHSA-w2r7-9579-27hf

vLLM denial of service vulnerability

High7.5CVE-2024-8768 · Published Sep 17, 2024 · updated Aug 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
vllm
PyPI
< 0.5.50.5.5
Details and references

A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-617
Also known as
CVE-2024-8768, PYSEC-2026-2024

More vLLM advisories

All vLLM
DateAdvisory
Sep 172024vLLM Denial of Service via the best_of parameter
CVE-2024-8939Medium6.2no fix yet
Jan 272025vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator
CVE-2025-24357High7.5fixed in 0.7.0
Feb 62025vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache
CVE-2025-25183Low2.6fixed in 0.7.2
Mar 192025vLLM denial of service via outlines unbounded cache on disk
CVE-2025-29770Medium6.5fixed in 0.8.0
Mar 192025vLLM Allows Remote Code Execution via Mooncake Integration
CVE-2025-29783Critical9.0fixed in 0.8.0
Mar 202025vLLM Deserialization of Untrusted Data vulnerability
CVE-2024-11041Critical9.8no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.