CVE-2025-48956: vLLM API endpoints vulnerable to Denial of Service Attacks

Published Aug 21, 2025
·
Updated

Summary A Denial of Service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large header to an HTTP endpoint. This results in server memory exhaustion, potentially leading to a crash or unresponsiveness. The attack does not require authentication, making it exploitable by any remote user.

Details The vulnerability leverages the abuse of HTTP headers. By setting a header such as X-Forwarded-For to a very large value like ("A" 5800000000), the server's HTTP parser or application logic may attempt to load the entire request into memory, overwhelming system resources.

Impact What kind of vulnerability is it? Who is impacted? Type of vulnerability: Denial of Service (DoS)

Resolution Upgrade to a version of vLLM that includes appropriate HTTP limits by deafult, or use a proxy in front of vLLM which provides protection against this issue.

Other sources

vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.10.1.1, a Denial of Service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large header to an HTTP endpoint. This results in server memory exhaustion, potentially leading to a crash or unresponsiveness. The attack does not require authentication, making it exploitable by any remote user. This vulnerability is fixed in 0.10.1.1.

MITRE

Affected Software

2 affected componentsFixes available
pip/vllm>=0.1.0<0.10.1.1
0.10.1.1
vllm vllm>=0.1.0<0.10.1.1

Event History

Aug 21, 2025
Advisory Published
via GitHub·02:24 PM
Data Sourced
via GitHub·02:24 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
RemedyAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-48956?

CVE-2025-48956 is classified as a Denial of Service (DoS) vulnerability that can lead to server memory exhaustion.

2

How do I fix CVE-2025-48956?

To mitigate CVE-2025-48956, update the affected vllm package to version 0.10.1.1 or later.

3

What type of attack exploits CVE-2025-48956?

CVE-2025-48956 can be exploited by sending a single HTTP GET request with an extremely large header.

4

What is the impact of CVE-2025-48956 on my server?

Exploiting CVE-2025-48956 can lead to memory exhaustion, causing the server to crash or become unresponsive.

5

Is authentication required to exploit CVE-2025-48956?

No, CVE-2025-48956 does not require authentication to exploit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203