Where
-Infinity
0

vllmvLLM: Remote DoS in vLLM via Invalid Recovered Token Reinjection

Risk 43
Severity
7.5
First published (updated )

vllmvLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a…

Risk 33
Severity
7
First published (updated )

vllmvLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings p…

Risk 33
Severity
7
First published (updated )

vllmvLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.…

Risk 33
Severity
7
First published (updated )

vllmvLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

vllmvLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1…

Risk 33
Severity
7
First published (updated )

vllmSSRF

Risk 33
Severity
7
First published (updated )

vllmvLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.…

Risk 77
First published (updated )

vllmSSRF

Risk 33
Severity
7
First published (updated )

vllmvLLM vulnerable to Server-Side Request Forgery (SSRF) in `MediaConnector`

Risk 35
Severity
7.1
EPSS
0.01%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

vllmvLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1…

Risk 33
Severity
7
First published (updated )

vllmvLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions

Risk 31
Severity
7.5
EPSS
0.05%
First published (updated )

vllm vllmvLLM Allows Remote Code Execution via PyNcclPipe Communication Service

Risk 61
Severity
9.8
EPSS
0.06%
First published (updated )

pip/vllmvLLM phi4mm: Quadratic Time Complexity in Input Token Processing​ leads to denial of service

Risk 31
Severity
7.5
EPSS
0.04%
First published (updated )

vllm vllmvLLM Vulnerable to Remote Code Execution via Mooncake Integration

Risk 87
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/vllmData exposure via ZeroMQ on multi-node vLLM deployment

Risk 43
Severity
7.5
First published (updated )

vllm-project vllmDenial of Service in vllm-project/vllm

Risk 35
Severity
7.5
First published (updated )

vllm-project vllmRemote Code Execution in vllm-project/vllm

Risk 86
Severity
9.8
First published (updated )

vllm-project vllmRemote Code Execution in vllm-project/vllm

Risk 86
Severity
9.8
First published (updated )

vllm-project vllmRemote Code Execution by Pickle Deserialization in vllm-project/vllm

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

vllm AIBrixvLLM AIBrix Prefix Caching hash.go random values

Risk 15
Severity
2.6
First published (updated )

vllm vllmvLLM allows a malicious model RCE by torch.load in hf_model_weights_iterator

Risk 56
Severity
8.8
EPSS
0.04%
First published (updated )

vllm vllmA completions API request with an empty prompt will crash the vllm API server. The impact is limite…

Risk 33
Severity
7
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203