vllm
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 67 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from September 12, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →vLLM through 0.29.0 Denial of Service via NIXL Multi-Prompt Assertion Failure
vLLM through 0.29.0 Adjacent-Request Sampler State Corruption via Unvalidated Prompt Token IDs
vLLM before 0.28.0 Denial of Service via negative token ID
vLLM through 0.29.0 Memory Exhaustion via Rejected Requests
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
vLLM before 0.28.0 Denial of Service via Audio Header
vLLM before 0.28.0 Denial of Service via audio extraction
vLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processor
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of CVE-2026-55574
Monitor vllm in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.