vLLM Vulnerabilities

pip LLM Inference

AI Threat Alert tracks 93 known vulnerabilities in vLLM, 11 rated critical — an AI/ML llm inference in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
61
Risk Score
93
Total CVEs
11
Critical
pip
Ecosystem
Aug 17, 2026
Last CVE
24%
Patch Rate
49d
Avg Time to Patch
89,146 stars 20,745 forks 6,638 issues 128 dependents Last push Aug 16, 2026
View on GitHub

Known Vulnerabilities (93 total, page 1 of 4)

Severity CVE ID Summary CVSS Published
HIGH GHSA-j659-8xh6-5pq5 atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard -- Aug 17, 2026 MEDIUM CVE-2026-73559 vLLM: unbounded prompt batch triggers single-request DoS 6.5 Aug 13, 2026 MEDIUM CVE-2026-73558 vLLM: integer overflow leaks other users' output 5.3 Aug 13, 2026 UNKNOWN CVE-2026-73557 vLLM: race condition bypasses prompt-embeds tensor guard -- Aug 13, 2026 MEDIUM CVE-2026-73556 vLLM: ReDoS in structured output stalls engine 5.3 Aug 13, 2026 MEDIUM CVE-2026-73555 vLLM: verbose errors leak host paths & usernames 5.3 Aug 13, 2026 HIGH CVE-2026-18621 OpenShift AI Pipelines: confused deputy grants node-root 7.6 Aug 10, 2026 HIGH CVE-2023-52355 libtiff: OOM DoS in vLLM inference container images 7.5 Jan 25, 2024 HIGH CVE-2026-55574 vLLM: unbounded regex compile hangs inference worker (ReDoS) 7.5 Jul 6, 2026 MEDIUM CVE-2026-55514 vLLM: malformed prompt embeds crash serving via M-RoPE 6.5 Jul 6, 2026 HIGH CVE-2026-54234 vLLM: crafted spec-decoding request crashes GPU worker (DoS) 7.5 Jul 6, 2026 MEDIUM CVE-2026-55646 vLLM: audio upload OOMs process before size check 6.5 Jul 6, 2026 HIGH CVE-2026-33845 GnuTLS: DTLS integer underflow enables OOB read/DoS 7.5 Apr 30, 2026 HIGH CVE-2026-42009 gnutls: DTLS packet-reorder bug DoS hits AI inference servers 7.5 May 18, 2026 HIGH CVE-2026-33846 GnuTLS: DTLS fragment heap overflow, DoS on AI inference 7.5 May 4, 2026 HIGH CVE-2026-42010 gnutls: NUL-byte username bypasses RSA-PSK auth 7.1 May 7, 2026 HIGH CVE-2026-56209 libaom: arbitrary address write in AV1 SVC codec 7.1 Jun 19, 2026 HIGH CVE-2026-56211 libaom: AV1 SVC OOB write enables RCE 7.1 Jun 19, 2026 HIGH CVE-2026-56210 libaom: AV1 SVC bounds-check miss leaks heap, crashes 7.1 Jun 19, 2026 HIGH CVE-2026-56208 libaom: heap overflow in AV1 encoder LAP mode 7.6 Jun 19, 2026 MEDIUM CVE-2026-4878 libcap: TOCTOU race in cap_set_file() enables privesc 6.7 Apr 9, 2026 HIGH CVE-2026-4775 libtiff: integer overflow causes heap OOB write 7.8 Mar 24, 2026 HIGH CVE-2026-10118 Poppler: PDF integer overflow enables heap RCE 7.8 Jun 1, 2026 HIGH CVE-2025-5318 libssh: OOB read in SFTP handle leaks memory 8.1 Jun 24, 2025 HIGH CVE-2025-9900 libtiff: arbitrary write via crafted TIFF image 8.8 Sep 23, 2025

Showing 1–25 of 93

Frequently asked questions

What is vLLM?

vLLM is an AI/ML llm inference tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does vLLM have?

vLLM has 93 known CVEs, 11 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is vLLM distributed in?

vLLM is distributed via the pip ecosystem and categorized as llm inference.

Where does the vLLM vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of vLLM?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor vLLM in your stack

Get instant alerts when new vulnerabilities affect vLLM. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring