vLLM Vulnerabilities

pip LLM Inference

AI Threat Alert tracks 115 known vulnerabilities in vLLM, 12 rated critical — an AI/ML llm inference in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
61
Risk Score
115
Total CVEs
12
Critical
pip
Ecosystem
Sep 24, 2026
Last CVE
26%
Patch Rate
47d
Avg Time to Patch
92,736 stars 22,697 forks 8,318 issues 95 dependents Last push Sep 27, 2026
View on GitHub

Known Vulnerabilities (115 total, page 1 of 5)

Severity CVE ID Summary CVSS Published
LOW CVE-2025-6170 A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections. 2.5 Jun 16, 2025 MEDIUM CVE-2026-58015 A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash. 5.9 Jun 30, 2026 HIGH CVE-2026-58014 A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary. 7.3 Jun 30, 2026 MEDIUM CVE-2026-58011 A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service. 6.5 Jun 30, 2026 HIGH CVE-2026-16118 A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 byte 7.1 Jul 17, 2026 MEDIUM CVE-2026-58013 A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary. 6.5 Jun 30, 2026 MEDIUM CVE-2026-58012 A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary. 6.5 Jun 30, 2026 MEDIUM CVE-2026-58010 A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary. 6.5 Jun 30, 2026 MEDIUM CVE-2026-15588 A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang. 5.3 Jul 20, 2026 CRITICAL CVE-2026-61732 Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into LLM messages without neutralizing ChatML special-token literals. Under the BYOK (Bring Your Own Key) deployment model, users configure their own LLM credentials to any OpenAI-compatible endpoint. Most open-source and self-deployed model providers (vLLM, SGLang, Ollama, LM Studio, text-generation-webui, etc.) do not filter spe 10.0 Sep 24, 2026 HIGH CVE-2026-92925 A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS). 7.1 Sep 17, 2026 MEDIUM CVE-2026-69147 vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, and MediaConnector.fetch_video forwards that choice to VideoMediaIO even when startup configuration selected a software decoder. The engine's _reserve_mm_ipc_gpu_memory logic budgets decoder memory only from static configuration, so the request-selected VIDEO_LOADER_REGISTRY backend can create a CUDA c 6.5 Sep 16, 2026 MEDIUM CVE-2026-57173 vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls AudioMediaIO.load_bytes or AudioMediaIO.load_file without passing VLLM_MAX_AUDIO_DECODE_DURATION_S to the shared audio decoder. An unauthenticated client can therefore submit a small compressed audio input that expands into a very large float32 PCM allocation, bypassing the duration guard already used by /v1/audio/transcriptions and causing an out-of-me 6.5 Sep 16, 2026 LOW CVE-2026-90713 vLLM: local DoS via malformed tiktoken vocab file 3.3 Sep 14, 2026 MEDIUM CVE-2026-90555 vLLM: FLAC header spoofing crashes transcription API 6.5 Sep 12, 2026 HIGH CVE-2026-90554 vLLM: audio decode DoS via NanoNemotronVL video input 7.5 Sep 12, 2026 HIGH CVE-2026-90553 vLLM: RCE bypasses trust_remote_code model safeguard 7.8 Sep 12, 2026 HIGH GHSA-wfgq-w7cq-qj7j mistral.rs: SSRF & file-read via image/audio URLs 7.2 Sep 10, 2026 HIGH CVE-2026-37237 vLLM: unbounded media URLs cause memory-exhaustion DoS 7.5 Aug 28, 2026 MEDIUM CVE-2026-18393 FFmpeg: heap overflow via crafted TDSC cursor in video 5.4 Aug 28, 2026 MEDIUM CVE-2026-78684 vLLM: unauthenticated DoS via DeepStream decode bypass 5.3 Aug 25, 2026 HIGH GHSA-j659-8xh6-5pq5 atomic-agents: unpriced models silently bypass cost cap -- Aug 17, 2026 MEDIUM CVE-2026-73560 vLLM: SSRF/LFI bypass in MiMo-V2 multimodal input 6.5 Aug 17, 2026 MEDIUM CVE-2026-71486 vLLM: unbounded /derender inputs cause resource DoS 4.3 Aug 17, 2026 MEDIUM CVE-2026-73559 vLLM: unbounded prompt batch triggers single-request DoS 6.5 Aug 13, 2026

Showing 1–25 of 115

Frequently asked questions

What is vLLM?

vLLM is an AI/ML llm inference tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does vLLM have?

vLLM has 115 known CVEs, 12 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is vLLM distributed in?

vLLM is distributed via the pip ecosystem and categorized as llm inference.

Where does the vLLM vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of vLLM?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor vLLM in your stack

Get instant alerts when new vulnerabilities affect vLLM. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring