Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting vllm.
- CVE-2026-55514vLLM denial of service via prompt embeds on M-RoPE models6.5
- CVE-2026-55574vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends7.5
- CVE-2026-54234vLLM: Remote DoS in vLLM via Invalid Recovered Token Reinjection7.5
- CVE-2026-55646vLLM speech-to-text endpoints allocate full upload before enforcing the audio file-size limit6.5
- CVE-2026-47155vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors6.5
- CVE-2026-41523vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution7.5
- CVE-2026-54232vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile8.8
- CVE-2026-54233vLLM: OOM Denial of Service via Audio Decompression Bomb6.5
- CVE-2026-54236vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router5.3
- CVE-2026-54235vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels6.5
- CVE-2026-48746vLLM: OpenAI auth bypass9.1
- CVE-2026-53923vLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overflow7.5
- CVE-2026-56340vLLM - Denial of Service via Unvalidated Multimodal Embeddings8.8
- CVE-2025-71379vllm - Regular Expression Denial of Service in Multiple Components4.3
- CVE-2026-5497Unbounded Frame Count in video/jpeg Base64 Data URL Processing Leads to OOM DoS in vllm-project/vllm7.5