Vulnerability index

Browse CVEs

48 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-55574 vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter pas… Vllm 0.24.0+ Fix from $1,9502026-07-06 MEDIUM 6.5 CVE-2026-55514 vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with… Vllm 0.24.0+ Fix from $1,6002026-07-06 HIGH 7.5 CVE-2026-54234 vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative dec… Vllm 0.24.0+ Fix from $1,9502026-07-06 MEDIUM 6.5 CVE-2026-55646 vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions and /v1/audio/translations rou… Vllm 0.24.0+ Fix from $1,6002026-07-06 MEDIUM 6.5 CVE-2026-54233 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcriptions endpoint limits compres… Vllm 0.23.1+ Fix from $1,6002026-06-22 MEDIUM 6.5 CVE-2026-54235 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation gates use comparison operator… Vllm 0.23.1+ Fix from $1,6002026-06-22 MEDIUM 5.3 CVE-2026-54236 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778, which introduced a sanitize… Vllm 0.23.1+ Fix from $1,6002026-06-22 CRITICAL 9.1 CVE-2026-48746 vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette'… Vllm 0.22.0+ Fix from $2,3002026-06-22 HIGH 8.8 CVE-2026-54232 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusio… Vllm 0.22.1+ Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-41523 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation functi… Vllm 0.22.0+ Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-53923 vLLM is an inference and serving engine for large language models (LLMs). From 0.5.5 until 0.23.1rc0, integer truncation of tensor dimensions in vLLM… Vllm 0.23.1+ Fix from $1,9502026-06-22 MEDIUM 6.5 CVE-2026-47155 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning controls do not consistently apply… Vllm 0.22.0+ Fix from $1,6002026-06-22 HIGH 7.5 CVE-2025-71379 vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lo… Vllm 0.9.0+ Fix from $1,9502026-06-20 HIGH 7.5 CVE-2026-56340 vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor… Vllm 0.13.0+ Fix from $1,9502026-06-20 HIGH 7.5 CVE-2026-5497 vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the … Vllm 0.19.0+ Fix from $1,9502026-06-11 HIGH 7.5 CVE-2026-44222 vLLM is an inference and serving engine for large language models (LLMs). From 0.6.1 to before 0.20.0, there is a a Token Injection vulnerability in … Vllm 0.20.0+ Fix from $1,9502026-05-12 MEDIUM 6.5 CVE-2026-44223 vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidden_states speculative decodin… Vllm 0.20.0+ Fix from $1,6002026-05-12 MEDIUM 5.6 CVE-2026-7141 A vulnerability was found in vllm up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v1/kv_cache_interface.py of th… Vllm after 0.19.0 Fix from $1,6002026-04-27 MEDIUM 6.5 CVE-2026-34755 vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.load_base64() method at vllm/… Vllm 0.19.0+ Fix from $1,6002026-04-06 MEDIUM 6.5 CVE-2026-34756 vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in th… Vllm 0.19.0+ Fix from $1,6002026-04-06 MEDIUM 5.4 CVE-2026-34753 vLLM is an inference and serving engine for large language models (LLMs). From 0.16.0 to before 0.19.0, a server-side request forgery (SSRF) vulnerab… Vllm 0.19.0+ Fix from $1,6002026-04-06 HIGH 7.1 CVE-2026-34760 vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, Librosa defaults to using nump… Vllm 0.18.0+ Fix from $1,9502026-04-02 HIGH 8.8 CVE-2026-27893 vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implement… Vllm 0.18.0+ Fix from $1,9502026-03-27 CRITICAL 9.8 CVE-2026-25960 vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in… Vllm 0.17.0+ Fix from $2,3002026-03-09 CRITICAL 9.8 CVE-2026-22778 vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multim… Vllm 0.14.1+ Fix from $2,3002026-02-02 HIGH 7.1 CVE-2026-24779 vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability… Vllm 0.14.1+ Fix from $1,9502026-01-27 CRITICAL 9.8 CVE-2026-22807 vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging … Vllm 0.14.0+ Fix from $2,3002026-01-21 HIGH 7.5 CVE-2026-22773 vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine se… Vllm 0.12.0+ Fix from $1,9502026-01-10 HIGH 8.8 CVE-2025-66448 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a conf… Vllm 0.11.1+ Fix from $1,9502025-12-01 HIGH 8.8 CVE-2025-62164 vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability co… Vllm 0.11.1+ Fix from $1,9502025-11-21