Vulnerability index

Browse CVEs

48 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vllm HIGH 7.5
CVE-2026-55574

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter pas…

Fix: 0.24.0+
Fix from $1,950 2026-07-06
Vllm MEDIUM 6.5
CVE-2026-55514

vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with…

Fix: 0.24.0+
Fix from $1,600 2026-07-06
Vllm HIGH 7.5
CVE-2026-54234

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative dec…

Fix: 0.24.0+
Fix from $1,950 2026-07-06
Vllm MEDIUM 6.5
CVE-2026-55646

vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions and /v1/audio/translations rou…

Fix: 0.24.0+
Fix from $1,600 2026-07-06
Vllm MEDIUM 6.5
CVE-2026-54233

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcriptions endpoint limits compres…

Fix: 0.23.1+
Fix from $1,600 2026-06-22
Vllm MEDIUM 6.5
CVE-2026-54235

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation gates use comparison operator…

Fix: 0.23.1+
Fix from $1,600 2026-06-22
Vllm MEDIUM 5.3
CVE-2026-54236

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778, which introduced a sanitize…

Fix: 0.23.1+
Fix from $1,600 2026-06-22
Vllm CRITICAL 9.1
CVE-2026-48746

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette'…

Fix: 0.22.0+
Fix from $2,300 2026-06-22
Vllm HIGH 8.8
CVE-2026-54232

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusio…

Fix: 0.22.1+
Fix from $1,950 2026-06-22
Vllm HIGH 7.5
CVE-2026-41523

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation functi…

Fix: 0.22.0+
Fix from $1,950 2026-06-22
Vllm HIGH 7.5
CVE-2026-53923

vLLM is an inference and serving engine for large language models (LLMs). From 0.5.5 until 0.23.1rc0, integer truncation of tensor dimensions in vLLM…

Fix: 0.23.1+
Fix from $1,950 2026-06-22
Vllm MEDIUM 6.5
CVE-2026-47155

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning controls do not consistently apply…

Fix: 0.22.0+
Fix from $1,600 2026-06-22
Vllm HIGH 7.5
CVE-2025-71379

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lo…

Fix: 0.9.0+
Fix from $1,950 2026-06-20
Vllm HIGH 7.5
CVE-2026-56340

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor…

Fix: 0.13.0+
Fix from $1,950 2026-06-20
Vllm HIGH 7.5
CVE-2026-5497

vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the …

Fix: 0.19.0+
Fix from $1,950 2026-06-11
Vllm HIGH 7.5
CVE-2026-44222

vLLM is an inference and serving engine for large language models (LLMs). From 0.6.1 to before 0.20.0, there is a a Token Injection vulnerability in …

Fix: 0.20.0+
Fix from $1,950 2026-05-12
Vllm MEDIUM 6.5
CVE-2026-44223

vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidden_states speculative decodin…

Fix: 0.20.0+
Fix from $1,600 2026-05-12
Vllm MEDIUM 5.6
CVE-2026-7141

A vulnerability was found in vllm up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v1/kv_cache_interface.py of th…

Fix: after 0.19.0
Fix from $1,600 2026-04-27
Vllm MEDIUM 6.5
CVE-2026-34755

vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.load_base64() method at vllm/…

Fix: 0.19.0+
Fix from $1,600 2026-04-06
Vllm MEDIUM 6.5
CVE-2026-34756

vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in th…

Fix: 0.19.0+
Fix from $1,600 2026-04-06
Vllm MEDIUM 5.4
CVE-2026-34753

vLLM is an inference and serving engine for large language models (LLMs). From 0.16.0 to before 0.19.0, a server-side request forgery (SSRF) vulnerab…

Fix: 0.19.0+
Fix from $1,600 2026-04-06
Vllm HIGH 7.1
CVE-2026-34760

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, Librosa defaults to using nump…

Fix: 0.18.0+
Fix from $1,950 2026-04-02
Vllm HIGH 8.8
CVE-2026-27893

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implement…

Fix: 0.18.0+
Fix from $1,950 2026-03-27
Vllm CRITICAL 9.8
CVE-2026-25960

vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in…

Fix: 0.17.0+
Fix from $2,300 2026-03-09
Vllm CRITICAL 9.8
CVE-2026-22778

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multim…

Fix: 0.14.1+
Fix from $2,300 2026-02-02
Vllm HIGH 7.1
CVE-2026-24779

vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability…

Fix: 0.14.1+
Fix from $1,950 2026-01-27
Vllm CRITICAL 9.8
CVE-2026-22807

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging …

Fix: 0.14.0+
Fix from $2,300 2026-01-21
Vllm HIGH 7.5
CVE-2026-22773

vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine se…

Fix: 0.12.0+
Fix from $1,950 2026-01-10
Vllm HIGH 8.8
CVE-2025-66448

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a conf…

Fix: 0.11.1+
Fix from $1,950 2025-12-01
Vllm HIGH 8.8
CVE-2025-62164

vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability co…

Fix: 0.11.1+
Fix from $1,950 2025-11-21