Vllm
This hub aggregates every CVE we track for Vllm, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
91
CVEs tracked
7
Critical
28
High
0
In CISA KEV
Severity distribution
MEDIUM42HIGH28CRITICAL7LOW6
Monthly trend
0
0
0
1
1
4
5
9
0
0
2
0
3
3
1
4
1
2
5
3
13
4
8
20
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Vllm.
- CVE-2026-94627vLLM through 0.29.0 GPU KV Cache Leak via Mooncake Transfer ID Collision7.5
- CVE-2026-94626vLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_size7.5
- CVE-2026-94625vLLM through 0.29.0 Resource Exhaustion via Ownerless Mooncake Transfer Placeholders5.3
- CVE-2026-94624vLLM through 0.29.0 Denial of Service via Unbounded P2P KV Offloading Sessions7.5
- CVE-2026-94623vLLM through 0.29.0 Denial of Service via NIXL Multi-Prompt Assertion Failure7.5
- CVE-2026-94622vLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer Metadata7.5
- CVE-2026-93989vLLM through 0.29.0 Cross-Request Logits Corruption via bad_words3.1
- CVE-2026-93840vLLM before 0.29.0 Cross-Request Logits Corruption via allowed_token_ids3.7
- CVE-2026-93841vLLM through 0.29.0 Adjacent-Request Sampler State Corruption via Unvalidated Prompt Token IDs3.7
- CVE-2026-93592vLLM before 0.28.0 Denial of Service via negative token ID7.5
- CVE-2026-93436vLLM through 0.29.0 Memory Exhaustion via Rejected Requests7.5
- CVE-2026-69147vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation6.5
- CVE-2026-57173vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions6.5
- CVE-2026-92365vllm-project vllm thinking_budget_state.py algorithmic complexity4.3
- CVE-2026-92220vllm-project vLLM MoRIIO Acknowledgement moriio_connector.py MoRIIOWrapper._handle_release_message resource consumption5.3
Product normalization is registry-driven with AI assist and human review. How it works