Where
-Infinity
0

vllm vllmvLLM denial of service via prompt embeds on M-RoPE models

Risk 40
Severity
7.1
First published (updated )

vllm vllmvLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends

Risk 47
Severity
8.7
First published (updated )

vllmvLLM: Remote DoS in vLLM via Invalid Recovered Token Reinjection

Risk 43
Severity
7.5
First published (updated )

vllm vllmvLLM speech-to-text endpoints allocate full upload before enforcing the audio file-size limit

Risk 38
Severity
6.5
First published (updated )

vllm vllmvLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pypi/vllmvLLM: Dependency Confusion Vulnerability in vLLM Dockerfile

Risk 77
Severity
8.8
First published (updated )

pypi/vllmvLLM - Denial of Service via Unvalidated Multimodal Embeddings

Risk 79
Severity
8.7
First published (updated )

pypi/vllmvllm - Regular Expression Denial of Service in Multiple Components

Risk 43
Severity
5.3
First published (updated )

pip/vllmvLLM: OOM Denial of Service via Audio Decompression Bomb

Risk 38
Severity
6.5
First published (updated )

pip/vllmvLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/vllmvLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overflow

Risk 43
Severity
5.3
First published (updated )

pip/vllmvLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels

Risk 33
Severity
6.9
First published (updated )

pip/vllmvLLM: OpenAI auth bypass

Risk 66
Severity
9.1
First published (updated )

pip/vllmvLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution

Risk 69
Severity
7.5
First published (updated )

vllm vllmvLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attac…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pypi/vllmUnbounded Frame Count in video/jpeg Base64 Data URL Processing Leads to OOM DoS in vllm-project/vllm

Risk 43
Severity
7.5
First published (updated )

pip/vllmvLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors

Risk 45
Severity
6.5
First published (updated )

pip/vllmvLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters

Risk 38
Severity
6.5
First published (updated )

pip/vllmvLLM: Remote DoS via Special-Token Placeholders

Risk 43
Severity
7.5
First published (updated )

pypi/vllmvllm KV Block kv_cache_interface.py has_mamba_layers uninitialized resource

Risk 31
Severity
2.9
EPSS
0.07%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/vllmvLLM Affected by Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing

Risk 38
Severity
6.5
First published (updated )

pip/vllmvLLM affected by Server-Side Request Forgery (SSRF) in `download_bytes_from_url `

Risk 34
Severity
5.4
First published (updated )

pip/vllmvLLM Affected by Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server

Risk 38
Severity
6.5
First published (updated )

pypi/librosavLLM: Downmix Implementation Differences as Attack Vectors Against Audio AI Models

Risk 48
Severity
7.1
First published (updated )

pypi/vllmvLLM's hardcoded trust_remote_code=True in NemotronVL and KimiK25 bypasses user security opt-out

Risk 77
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/vllmSSRF Protection Bypass in vLLM

Risk 86
Severity
9.8
First published (updated )

pip/vllmvLLM leaks a heap address when PIL throws an error

Risk 61
Severity
9.8
EPSS
0.05%
First published (updated )

vllmvLLM vulnerable to Server-Side Request Forgery (SSRF) in `MediaConnector`

Risk 35
Severity
7.1
EPSS
0.01%
First published (updated )

pip/vllmvLLM affected by RCE via auto_map dynamic module loading during model initialization

Risk 61
Severity
9.8
EPSS
0.05%
First published (updated )

vllmvLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions

Risk 31
Severity
7.5
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203