Skip to content

vLLM security advisories

71 advisories · 18 critical or high in 12 months · latest Sep 17

60 of 71 advisories

DateAdvisory
Sep 17vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
CVE-2026-69147Medium6.5fixed in 0.28.0
Sep 16vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
CVE-2026-57173Medium6.5fixed in 0.24.0
Sep 12vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with
CVE-2026-90553High7.8fixed in 0.28.0
Sep 8vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
CVE-2026-73560Medium6.5fixed in 0.26.0
Sep 8vLLM: Cross-User Data Leak Vulnerability
CVE-2026-73558Medium5.3fixed in 0.27.0
Sep 4vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
CVE-2026-73557Mediumfixed in 0.26.0
Sep 4vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) , missed sibling of GHSA-rwxx-mrjm-wc2m
CVE-2026-73556Medium5.3fixed in 0.26.0
Sep 4vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
CVE-2026-73555Medium5.3fixed in 0.26.0
Sep 4vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
CVE-2026-71486Medium4.3fixed in 0.26.0
Aug 13vLLM: Completion prompt lists fan out into unbounded engine requests
CVE-2026-73559Medium6.5fixed in 0.26.0
Jul 20vLLM denial of service via prompt embeds on M-RoPE models
CVE-2026-55514Highfixed in 0.24.0
Jul 17vLLM: Speech-to-text upload size limit is enforced after full UploadFile read
CVE-2026-55646Medium6.5fixed in 0.24.0
Jul 17vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
CVE-2026-55574High7.5fixed in 0.24.0
Jul 17vLLM has Remote DoS via Invalid Recovered Token Reinjection
CVE-2026-54234High7.5fixed in 0.24.0
Jul 17vLLM: Processing differential in multi-channel audio downmixing enables hidden-input/moderation bypass for audio models
CVE-2026-34760Medium5.9fixed in 0.18.0
Jun 22vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusion attack through the flashinfer-jit-cache package. The package is installed from a custom index (flashinfer.ai/whl/) using --extra-index-url, but the p
CVE-2026-54232High8.8fixed in 0.22.1
Jun 17vLLM: OOM Denial of Service via Audio Decompression Bomb
CVE-2026-54233Medium6.5fixed in 0.24.0
Jun 17vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
CVE-2026-54236Medium5.3fixed in 0.24.0
Jun 17vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
CVE-2026-53923Medium7.5fixed in 0.24.0
Jun 17vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
CVE-2026-12491Medium4.8fixed in 0.24.0
Jun 17vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels
CVE-2026-54235Medium6.5fixed in 0.24.0
Jun 16vLLM: OpenAI auth bypass
CVE-2026-48746Critical9.1fixed in 0.22.0
Jun 16vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
CVE-2026-41523High7.5fixed in 0.22.0
Jun 11vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method
CVE-2026-5497High7.5fixed in 0.19.0
Jun 10vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
CVE-2026-47155Medium6.5fixed in 0.22.0
May 26vllm has Improper Resource Shutdown or Release
CVE-2026-9540Medium5.3no fix yet
May 6vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters
CVE-2026-44223Medium6.5fixed in 0.20.0
May 5vLLM Vulnerable to Remote DoS via Special-Token Placeholders
CVE-2026-44222Medium6.5fixed in 0.20.0
Apr 27vLLM makes Use of Uninitialized Resource
CVE-2026-7141Low5.6fixed in 0.19.1
Apr 3vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing
CVE-2026-34755Medium6.5fixed in 0.19.0
Apr 3vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `
CVE-2026-34753Medium5.4fixed in 0.19.0
Apr 3vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server
CVE-2026-34756Medium6.5fixed in 0.19.0
Mar 27vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out
CVE-2026-27893High8.8fixed in 0.18.0
Mar 9vLLM has SSRF Protection Bypass
CVE-2026-25960Medium5.4fixed in 0.17.0
Feb 2vLLM has RCE In Video Processing
CVE-2026-22778Critical9.8fixed in 0.14.1
Jan 28vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector
CVE-2026-24779High7.1fixed in 0.14.1
Jan 21vLLM affected by RCE via auto_map dynamic module loading during model initialization
CVE-2026-22807High8.8fixed in 0.14.0
Jan 13vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions
CVE-2026-22773Medium6.5fixed in 0.12.0
Jan 8vLLM introduced enhanced protection for CVE-2025-62164
CVE-2026-56340High8.8fixed in 0.13.0
Dec 22025vLLM vulnerable to remote code execution via transformers_utils/get_config
CVE-2025-66448High7.1fixed in 0.11.1
Nov 202025vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`
CVE-2025-62426Medium6.5fixed in 0.11.1
Nov 202025vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
CVE-2025-62372High6.5fixed in 0.11.1
Nov 202025vLLM deserialization vulnerability leading to DoS and potential RCE
CVE-2025-62164High8.8fixed in 0.11.1
Oct 72025vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
CVE-2025-6242High7.1fixed in 0.11.0
Oct 72025vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
CVE-2025-61620Medium6.5fixed in 0.11.0
Oct 72025vLLM is vulnerable to timing attack at bearer auth
CVE-2025-59425High7.5fixed in 0.11.0
Aug 212025vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
CVE-2025-9141High8.8fixed in 0.10.1.1
Aug 212025vllm API endpoints vulnerable to Denial of Service Attacks
CVE-2025-48956High7.5fixed in 0.10.1.1
May 282025vLLM Tool Schema allows DoS via Malformed pattern and type Fields
CVE-2025-48944Medium6.5fixed in 0.9.0
May 282025vLLM allows clients to crash the openai server with invalid regex
CVE-2025-48943Medium6.5fixed in 0.9.0
May 282025vLLM DOS: Remotely kill vllm over http with invalid JSON schema
CVE-2025-48942Medium6.5fixed in 0.9.0
May 282025vLLM has a Weakness in MultiModalHasher Image Hashing Implementation
CVE-2025-46722Medium4.2fixed in 0.9.0
May 282025Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
CVE-2025-46570Low2.6fixed in 0.9.0
May 282025vLLM vulnerable to Regular Expression Denial of Service
CVE-2025-71379Medium4.3fixed in 0.9.0
May 282025vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`
CVE-2025-48887Medium6.5fixed in 0.9.0
May 202025vLLM Allows Remote Code Execution via PyNcclPipe Communication Service
CVE-2025-47277Critical9.8fixed in 0.8.5
May 62025Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
CVE-2025-30165High8.0fixed in 0.10.0
Apr 292025vLLM: Quadratic Time Complexity in Input Token Processing​ leads to denial of service
CVE-2025-46560Medium6.5fixed in 0.8.5
Apr 292025vLLM Vulnerable to Remote Code Execution via Mooncake Integration
CVE-2025-32444Critical10.0fixed in 0.8.5
Apr 292025Data exposure via ZeroMQ on multi-node vLLM deployment
CVE-2025-30202High7.5fixed in 0.8.5
About vLLM

The high-throughput LLM inference and serving engine.

Packages watched: vllm (PyPI).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.