vLLM Vulnerabilities

pip LLM Inference

AI Threat Alert tracks 93 known vulnerabilities in vLLM, 11 rated critical — an AI/ML llm inference in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
61
Risk Score
93
Total CVEs
11
Critical
pip
Ecosystem
Aug 17, 2026
Last CVE
24%
Patch Rate
49d
Avg Time to Patch
89,146 stars 20,745 forks 6,638 issues 128 dependents Last push Aug 16, 2026
View on GitHub

Known Vulnerabilities (93 total, page 2 of 4)

Severity CVE ID Summary CVSS Published
HIGH CVE-2026-54232 vLLM: dependency confusion RCE backdoors container images 8.8 Jun 22, 2026 HIGH CVE-2026-56340 vLLM: sparse tensor DoS/memory corruption via embeddings 7.5 Jun 20, 2026 HIGH CVE-2025-71379 vLLM: ReDoS via crafted API input causes DoS 7.5 Jun 20, 2026 MEDIUM CVE-2026-12706 FFmpeg RASC: UAF in decoder crashes AI inference containers 6.5 Jun 19, 2026 MEDIUM CVE-2026-54235 vLLM: NaN/Inf bypass crashes GPU inference workers 6.5 Jun 17, 2026 MEDIUM GHSA-8jr5-v98p-w75m vllm: EXIF/tRNS preprocessing gap enables adversarial input 4.8 Jun 17, 2026 HIGH CVE-2026-53923 vLLM: integer truncation leaks GPU memory cross-tenant 7.5 Jun 17, 2026 MEDIUM CVE-2026-54236 vLLM: heap address leak enables ASLR bypass 5.3 Jun 17, 2026 MEDIUM CVE-2026-54233 vLLM: decompression bomb OOM via audio endpoint 6.5 Jun 17, 2026 MEDIUM CVE-2026-12491 vLLM: image metadata mishandling corrupts multimodal inputs 4.8 Jun 17, 2026 HIGH CVE-2026-41523 vLLM: assert bypass → RCE via poisoned HuggingFace model 7.5 Jun 16, 2026 CRITICAL CVE-2026-48746 vllm: auth bypass exposes OpenAI inference API 9.1 Jun 16, 2026 HIGH CVE-2026-5201 gdk-pixbuf: JPEG heap overflow crashes vLLM inference 7.5 Mar 31, 2026 HIGH CVE-2026-4111 libarchive: infinite loop DoS in RAR5 decompression 7.5 Mar 13, 2026 MEDIUM CVE-2025-14831 GnuTLS: TLS cert parsing DoS hits vllm inference 5.3 Feb 9, 2026 HIGH CVE-2023-52356 libtiff: heap overflow DoS in vLLM inference via TIFF input 7.5 Jan 25, 2024 HIGH CVE-2026-5121 libarchive: integer overflow in zisofs hits vllm containers 7.5 Mar 30, 2026 HIGH CVE-2026-4424 libarchive: RAR heap OOB read leaks memory in vLLM stacks 7.5 Mar 19, 2026 LOW CVE-2026-10813 LMCache: weak hash enables KV cache integrity bypass 3.6 Jun 4, 2026 HIGH CVE-2026-5497 vLLM: unauthenticated OOM DoS via video frame parsing 7.5 Jun 11, 2026 MEDIUM CVE-2026-47155 vLLM: revision pin bypass loads unreviewed artifacts 6.5 Jun 10, 2026 UNKNOWN CVE-2026-4944 vllm: trust_remote_code bypass enables RCE via HuggingFace -- May 28, 2026 MEDIUM CVE-2026-9540 vllm: unauthenticated DoS in OpenAI-compatible serving path 5.3 May 26, 2026 HIGH CVE-2026-46517 LMDeploy: hardcoded trust_remote_code enables RCE 7.8 May 21, 2026 MEDIUM CVE-2026-44223 vLLM: speculative decoding DoS via penalty params 6.5 May 6, 2026

Showing 26–50 of 93

Frequently asked questions

What is vLLM?

vLLM is an AI/ML llm inference tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does vLLM have?

vLLM has 93 known CVEs, 11 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is vLLM distributed in?

vLLM is distributed via the pip ecosystem and categorized as llm inference.

Where does the vLLM vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of vLLM?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor vLLM in your stack

Get instant alerts when new vulnerabilities affect vLLM. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring