| Sep 17 | vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation CVE-2026-69147Medium6.5fixed in 0.28.0 | Medium6.5 | 0.28.0 |
| Sep 16 | vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions CVE-2026-57173Medium6.5fixed in 0.24.0 | Medium6.5 | 0.24.0 |
| Sep 12 | vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with CVE-2026-90553High7.8fixed in 0.28.0 | High7.8 | 0.28.0 |
| Sep 8 | vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections CVE-2026-73560Medium6.5fixed in 0.26.0 | Medium6.5 | 0.26.0 |
| Sep 8 | vLLM: Cross-User Data Leak Vulnerability CVE-2026-73558Medium5.3fixed in 0.27.0 | Medium5.3 | 0.27.0 |
| Sep 4 | vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts CVE-2026-73557Mediumfixed in 0.26.0 | Medium | 0.26.0 |
| Sep 4 | vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) , missed sibling of GHSA-rwxx-mrjm-wc2m CVE-2026-73556Medium5.3fixed in 0.26.0 | Medium5.3 | 0.26.0 |
| Sep 4 | vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages CVE-2026-73555Medium5.3fixed in 0.26.0 | Medium5.3 | 0.26.0 |
| Sep 4 | vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds CVE-2026-71486Medium4.3fixed in 0.26.0 | Medium4.3 | 0.26.0 |
| Aug 13 | vLLM: Completion prompt lists fan out into unbounded engine requests CVE-2026-73559Medium6.5fixed in 0.26.0 | Medium6.5 | 0.26.0 |
| Jul 20 | vLLM denial of service via prompt embeds on M-RoPE models CVE-2026-55514Highfixed in 0.24.0 | High | 0.24.0 |
| Jul 17 | vLLM: Speech-to-text upload size limit is enforced after full UploadFile read CVE-2026-55646Medium6.5fixed in 0.24.0 | Medium6.5 | 0.24.0 |
| Jul 17 | vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends CVE-2026-55574High7.5fixed in 0.24.0 | High7.5 | 0.24.0 |
| Jul 17 | vLLM has Remote DoS via Invalid Recovered Token Reinjection CVE-2026-54234High7.5fixed in 0.24.0 | High7.5 | 0.24.0 |
| Jul 17 | vLLM: Processing differential in multi-channel audio downmixing enables hidden-input/moderation bypass for audio models CVE-2026-34760Medium5.9fixed in 0.18.0 | Medium5.9 | 0.18.0 |
| Jun 22 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusion attack through the flashinfer-jit-cache package. The package is installed from a custom index (flashinfer.ai/whl/) using --extra-index-url, but the p CVE-2026-54232High8.8fixed in 0.22.1 | High8.8 | 0.22.1 |
| Jun 17 | vLLM: OOM Denial of Service via Audio Decompression Bomb CVE-2026-54233Medium6.5fixed in 0.24.0 | Medium6.5 | 0.24.0 |
| Jun 17 | vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router CVE-2026-54236Medium5.3fixed in 0.24.0 | Medium5.3 | 0.24.0 |
| Jun 17 | vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving CVE-2026-53923Medium7.5fixed in 0.24.0 | Medium7.5 | 0.24.0 |
| Jun 17 | vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations CVE-2026-12491Medium4.8fixed in 0.24.0 | Medium4.8 | 0.24.0 |
| Jun 17 | vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels CVE-2026-54235Medium6.5fixed in 0.24.0 | Medium6.5 | 0.24.0 |
| Jun 16 | vLLM: OpenAI auth bypass CVE-2026-48746Critical9.1fixed in 0.22.0 | Critical9.1 | 0.22.0 |
| Jun 16 | vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution CVE-2026-41523High7.5fixed in 0.22.0 | High7.5 | 0.22.0 |
| Jun 11 | vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method CVE-2026-5497High7.5fixed in 0.19.0 | High7.5 | 0.19.0 |
| Jun 10 | vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors CVE-2026-47155Medium6.5fixed in 0.22.0 | Medium6.5 | 0.22.0 |
| May 26 | vllm has Improper Resource Shutdown or Release CVE-2026-9540Medium5.3no fix yet | Medium5.3 | No fix yet |
| May 6 | vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters CVE-2026-44223Medium6.5fixed in 0.20.0 | Medium6.5 | 0.20.0 |
| May 5 | vLLM Vulnerable to Remote DoS via Special-Token Placeholders CVE-2026-44222Medium6.5fixed in 0.20.0 | Medium6.5 | 0.20.0 |
| Apr 27 | vLLM makes Use of Uninitialized Resource CVE-2026-7141Low5.6fixed in 0.19.1 | Low5.6 | 0.19.1 |
| Apr 3 | vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing CVE-2026-34755Medium6.5fixed in 0.19.0 | Medium6.5 | 0.19.0 |
| Apr 3 | vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url ` CVE-2026-34753Medium5.4fixed in 0.19.0 | Medium5.4 | 0.19.0 |
| Apr 3 | vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server CVE-2026-34756Medium6.5fixed in 0.19.0 | Medium6.5 | 0.19.0 |
| Mar 27 | vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out CVE-2026-27893High8.8fixed in 0.18.0 | High8.8 | 0.18.0 |
| Mar 9 | vLLM has SSRF Protection Bypass CVE-2026-25960Medium5.4fixed in 0.17.0 | Medium5.4 | 0.17.0 |
| Feb 2 | vLLM has RCE In Video Processing CVE-2026-22778Critical9.8fixed in 0.14.1 | Critical9.8 | 0.14.1 |
| Jan 28 | vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector CVE-2026-24779High7.1fixed in 0.14.1 | High7.1 | 0.14.1 |
| Jan 21 | vLLM affected by RCE via auto_map dynamic module loading during model initialization CVE-2026-22807High8.8fixed in 0.14.0 | High8.8 | 0.14.0 |
| Jan 13 | vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions CVE-2026-22773Medium6.5fixed in 0.12.0 | Medium6.5 | 0.12.0 |
| Jan 8 | vLLM introduced enhanced protection for CVE-2025-62164 CVE-2026-56340High8.8fixed in 0.13.0 | High8.8 | 0.13.0 |
| Dec 22025 | vLLM vulnerable to remote code execution via transformers_utils/get_config CVE-2025-66448High7.1fixed in 0.11.1 | High7.1 | 0.11.1 |
| Nov 202025 | vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs` CVE-2025-62426Medium6.5fixed in 0.11.1 | Medium6.5 | 0.11.1 |
| Nov 202025 | vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs CVE-2025-62372High6.5fixed in 0.11.1 | High6.5 | 0.11.1 |
| Nov 202025 | vLLM deserialization vulnerability leading to DoS and potential RCE CVE-2025-62164High8.8fixed in 0.11.1 | High8.8 | 0.11.1 |
| Oct 72025 | vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class CVE-2025-6242High7.1fixed in 0.11.0 | High7.1 | 0.11.0 |
| Oct 72025 | vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server CVE-2025-61620Medium6.5fixed in 0.11.0 | Medium6.5 | 0.11.0 |
| Oct 72025 | vLLM is vulnerable to timing attack at bearer auth CVE-2025-59425High7.5fixed in 0.11.0 | High7.5 | 0.11.0 |
| Aug 212025 | vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder CVE-2025-9141High8.8fixed in 0.10.1.1 | High8.8 | 0.10.1.1 |
| Aug 212025 | vllm API endpoints vulnerable to Denial of Service Attacks CVE-2025-48956High7.5fixed in 0.10.1.1 | High7.5 | 0.10.1.1 |
| May 282025 | vLLM Tool Schema allows DoS via Malformed pattern and type Fields CVE-2025-48944Medium6.5fixed in 0.9.0 | Medium6.5 | 0.9.0 |
| May 282025 | vLLM allows clients to crash the openai server with invalid regex CVE-2025-48943Medium6.5fixed in 0.9.0 | Medium6.5 | 0.9.0 |
| May 282025 | vLLM DOS: Remotely kill vllm over http with invalid JSON schema CVE-2025-48942Medium6.5fixed in 0.9.0 | Medium6.5 | 0.9.0 |
| May 282025 | vLLM has a Weakness in MultiModalHasher Image Hashing Implementation CVE-2025-46722Medium4.2fixed in 0.9.0 | Medium4.2 | 0.9.0 |
| May 282025 | Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching CVE-2025-46570Low2.6fixed in 0.9.0 | Low2.6 | 0.9.0 |
| May 282025 | vLLM vulnerable to Regular Expression Denial of Service CVE-2025-71379Medium4.3fixed in 0.9.0 | Medium4.3 | 0.9.0 |
| May 282025 | vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py` CVE-2025-48887Medium6.5fixed in 0.9.0 | Medium6.5 | 0.9.0 |
| May 202025 | vLLM Allows Remote Code Execution via PyNcclPipe Communication Service CVE-2025-47277Critical9.8fixed in 0.8.5 | Critical9.8 | 0.8.5 |
| May 62025 | Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration CVE-2025-30165High8.0fixed in 0.10.0 | High8.0 | 0.10.0 |
| Apr 292025 | vLLM: Quadratic Time Complexity in Input Token Processing leads to denial of service CVE-2025-46560Medium6.5fixed in 0.8.5 | Medium6.5 | 0.8.5 |
| Apr 292025 | vLLM Vulnerable to Remote Code Execution via Mooncake Integration CVE-2025-32444Critical10.0fixed in 0.8.5 | Critical10.0 | 0.8.5 |
| Apr 292025 | Data exposure via ZeroMQ on multi-node vLLM deployment CVE-2025-30202High7.5fixed in 0.8.5 | High7.5 | 0.8.5 |