CVE-2024-11040: Denial of Service in vllm-project/vllm
Published Mar 20, 2025
·Updated
Rejected reason: REJECT DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-8939. Notes: All CVE users should reference CVE-2024-8939 instead of this CVE Record. All references and descriptions in this candidate have been removed to prevent accidental usage.
Affected Software
1 affected component
vllm-project vllm
Event History
Mar 20, 2025
CVE Published
via MITRE·10:10 AM
Rejected
via MITRE·10:10 AM
Data Sourced
via NVD·10:15 AM
Description
Apr 15, 2025
Rejected
via MITRE·03:53 PM
Rejected
via NVD·04:15 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-11040?
CVE-2024-11040 is classified as a Denial of Service vulnerability.
2
How do I fix CVE-2024-11040?
To mitigate CVE-2024-11040, avoid enabling 'use_beam_search' or setting a high value for 'best_of' in the POST /v1/completions and POST /v1/embeddings endpoints.
3
What versions are affected by CVE-2024-11040?
CVE-2024-11040 affects vllm version 0.5.2.2.
4
What are the impacted endpoints in CVE-2024-11040?
The impacted endpoints for CVE-2024-11040 are 'POST /v1/completions' and 'POST /v1/embeddings'.
5
What kind of attack does CVE-2024-11040 facilitate?
CVE-2024-11040 facilitates Denial of Service attacks that can disrupt service availability.