Vulnerabilities in vllm-project
51 resultsVexday analysis
O vllm-project apresenta volume moderado de vulnerabilidades (51 CVEs) com concentração recente: 18 divulgadas nos últimos 90 dias. A fraqueza dominante (CWE-502 - Desserialização de dados não confiáveis) afeta 7 casos críticos, porém nenhuma vulnerabilidade está sob exploração ativa documentada (KEV). O risco é significativo pela cadência de descobertas recentes e pela natureza das falhas de desserialização, que tipicamente permitem execução remota de código.
CVE-2026-55574HIGHvLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backendsEPSS 0.3%CVE-2026-55646MEDIUMvLLM speech-to-text endpoints allocate full upload before enforcing the audio file-size limitEPSS 0.3%CVE-2026-53923MEDIUMvLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overflowEPSS 0.3%CVE-2025-46722MEDIUMvLLM has a Weakness in MultiModalHasher Image Hashing ImplementationEPSS 0.3%CVE-2026-54235MEDIUMvLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernelsEPSS 0.3%CVE-2026-34760MEDIUMvLLM: Downmix Implementation Differences as Attack Vectors Against Audio AI ModelsEPSS 0.3%CVE-2025-46570LOWvLLM’s Chunk-Based Prefix Caching Vulnerable to Potential Timing Side-ChannelEPSS 0.3%CVE-2026-34753MEDIUMvLLM affected by Server-Side Request Forgery (SSRF) in `download_bytes_from_url `EPSS 0.2%CVE-2026-12491MEDIUMVllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectationsEPSS 0.2%CVE-2026-47155MEDIUMvLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processorsEPSS 0.2%CVE-2025-25183LOWvLLM using built-in hash() from Python 3.12 leads to predictable hash collisions in vLLM prefix cacheEPSS 0.2%