Vllm
This hub aggregates every CVE we track for Vllm, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
49
CVEs tracked
7
Critical
17
High
0
In CISA KEV
Severity distribution
MEDIUM23HIGH17CRITICAL7LOW2
Monthly trend
0
0
2
0
0
0
1
1
4
3
8
0
0
1
0
2
3
1
3
1
2
5
3
9
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Vllm.
- CVE-2026-47155vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors6.5
- CVE-2026-41523vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution7.5
- CVE-2026-54232vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile8.8
- CVE-2026-54233vLLM: OOM Denial of Service via Audio Decompression Bomb6.5
- CVE-2026-54236vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router5.3
- CVE-2026-48746vLLM: OpenAI auth bypass9.1
- CVE-2026-56340vLLM - Denial of Service via Unvalidated Multimodal Embeddings8.8
- CVE-2025-71379vllm - Regular Expression Denial of Service in Multiple Components4.3
- CVE-2026-5497Unbounded Frame Count in video/jpeg Base64 Data URL Processing Leads to OOM DoS in vllm-project/vllm7.5
- CVE-2026-9540vllm-project vllm OpenAI-compatible Serving Path denial of service5.3
- CVE-2026-44223vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters6.5
- CVE-2026-44222vLLM: Remote DoS via Special-Token Placeholders6.5
- CVE-2026-7141vllm KV Block kv_cache_interface.py has_mamba_layers uninitialized resource5.6
- CVE-2026-34756vLLM Affected by Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server6.5
- CVE-2026-34755vLLM Affected by Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing6.5
Product normalization is registry-driven with AI assist and human review. How it works