Vllm
This hub aggregates every CVE we track for Vllm, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
56
CVEs tracked
7
Critical
20
High
0
In CISA KEV
Severity distribution
MEDIUM27HIGH20CRITICAL7LOW2
Monthly trend
2
0
0
0
1
1
4
3
8
0
0
1
0
2
3
1
3
1
2
5
3
12
4
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Vllm.
- CVE-2026-55514vLLM denial of service via prompt embeds on M-RoPE models6.5
- CVE-2026-55574vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends7.5
- CVE-2026-54234vLLM: Remote DoS in vLLM via Invalid Recovered Token Reinjection7.5
- CVE-2026-55646vLLM speech-to-text endpoints allocate full upload before enforcing the audio file-size limit6.5
- CVE-2026-47155vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors6.5
- CVE-2026-41523vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution7.5
- CVE-2026-54232vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile8.8
- CVE-2026-54233vLLM: OOM Denial of Service via Audio Decompression Bomb6.5
- CVE-2026-54236vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router5.3
- CVE-2026-54235vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels6.5
- CVE-2026-48746vLLM: OpenAI auth bypass9.1
- CVE-2026-53923vLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overflow7.5
- CVE-2026-56340vLLM - Denial of Service via Unvalidated Multimodal Embeddings8.8
- CVE-2025-71379vllm - Regular Expression Denial of Service in Multiple Components4.3
- CVE-2026-12491Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectations4.8
Product normalization is registry-driven with AI assist and human review. How it works