Vulnerabilidades en vllm-project
51 resultadosAnálisis Vexday
O vllm-project apresenta volume moderado de vulnerabilidades (51 CVEs) com concentração recente: 18 divulgadas nos últimos 90 dias. A fraqueza dominante (CWE-502 - Desserialização de dados não confiáveis) afeta 7 casos críticos, porém nenhuma vulnerabilidade está sob exploração ativa documentada (KEV). O risco é significativo pela cadência de descobertas recentes e pela natureza das falhas de desserialização, que tipicamente permitem execução remota de código.
CVE-2025-30165HIGHRemote Code Execution Vulnerability in vLLM Multi-Node Cluster ConfigurationEPSS 0.5%CVE-2026-24779HIGHvLLM vulnerable to Server-Side Request Forgery (SSRF) in `MediaConnector`EPSS 0.5%CVE-2025-59425HIGHvLLM vulnerable to timing attack at bearer authEPSS 0.5%CVE-2025-46560MEDIUMvLLM phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of serviceEPSS 0.5%CVE-2025-48942MEDIUMvLLM DOS: Remotely kill vllm over http with invalid JSON schemaEPSS 0.5%CVE-2025-48944MEDIUMvLLM Tool Schema allows DoS via Malformed pattern and type FieldsEPSS 0.4%CVE-2025-48887MEDIUMvLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`EPSS 0.4%CVE-2025-29770MEDIUMvLLM denial of service via outlines unbounded cache on diskEPSS 0.4%CVE-2026-9540MEDIUMvllm-project vllm OpenAI-compatible Serving Path denial of serviceEPSS 0.4%CVE-2026-54233MEDIUMvLLM: OOM Denial of Service via Audio Decompression BombEPSS 0.4%CVE-2025-48943MEDIUMvLLM allows clients to crash the openai server with invalid regexEPSS 0.4%CVE-2026-44222MEDIUMvLLM: Remote DoS via Special-Token PlaceholdersEPSS 0.4%CVE-2026-22773MEDIUMvLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensionsEPSS 0.4%CVE-2026-34755MEDIUMvLLM Affected by Denial of Service via Unbounded Frame Count in video/jpeg Base64 ProcessingEPSS 0.4%CVE-2026-55514HIGHvLLM denial of service via prompt embeds on M-RoPE modelsEPSS 0.4%CVE-2025-62372HIGHvLLM vulnerable to DoS with incorrect shape of multimodal embedding inputsEPSS 0.4%CVE-2026-44223MEDIUMvLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parametersEPSS 0.4%CVE-2026-54234HIGHvLLM: Remote DoS in vLLM via Invalid Recovered Token ReinjectionEPSS 0.4%CVE-2025-62426MEDIUMvLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`EPSS 0.4%CVE-2026-34756MEDIUMvLLM Affected by Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API ServerEPSS 0.3%