CVE-2025-32444: vLLM Vulnerable to Remote Code Execution via Mooncake Integration

Published Apr 29, 2025
·
Updated

Impacted Deployments

Note that vLLM instances that do NOT make use of the mooncake integration are NOT vulnerable.

Description

vLLM integration with mooncake is vaulnerable to remote code execution due to using pickle based serialization over unsecured ZeroMQ sockets. The vulnerable sockets were set to listen on all network interfaces, increasing the likelihood that an attacker is able to reach the vulnerable ZeroMQ sockets to carry out an attack.

This is a similar to GHSA - x3m8 - f7g5 - qhm7, the problem is in

https://github.com/vllm-project/vllm/blob/32b14baf8a1f7195ca09484de3008063569b43c5/vllm/distributed/kvtransfer/kvpipe/mooncakepipe.py#L179

Here recvpyobj() Contains implicit pickle.loads(), which leads to potential RCE.

Other sources

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and prior to 0.8.5, having vLLM integration with mooncake, are vulnerable to remote code execution due to using pickle based serialization over unsecured ZeroMQ sockets. The vulnerable sockets were set to listen on all network interfaces, increasing the likelihood that an attacker is able to reach the vulnerable ZeroMQ sockets to carry out an attack. vLLM instances that do not make use of the mooncake integration are not vulnerable. This issue has been patched in version 0.8.5.

MITRE

Affected Software

2 affected componentsFixes available
vllm vllm>=0.6.5<0.8.5
pip/vllm>=0.6.5<0.8.5
0.8.5

Event History

Apr 29, 2025
Advisory Published
via GitHub·02:52 PM
Apr 30, 2025
CVE Published
via MITRE·12:25 AM
Data Sourced
via MITRE·12:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-32444?

CVE-2025-32444 is classified as a critical vulnerability due to its potential for remote code execution.

2

How do I fix CVE-2025-32444?

To mitigate CVE-2025-32444, upgrade to a version of vLLM that is greater than 0.8.5 and ensure that mooncake integration is not in use.

3

Which versions of vLLM are affected by CVE-2025-32444?

Versions of vLLM from 0.6.5 to 0.8.5 are vulnerable to CVE-2025-32444.

4

What types of attacks can CVE-2025-32444 facilitate?

CVE-2025-32444 can facilitate remote code execution attacks due to the insecure use of `pickle` serialization over ZeroMQ.

5

What systems are primarily affected by CVE-2025-32444?

Only vLLM instances that utilize the mooncake integration are affected by CVE-2025-32444, while others remain secure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203