vLLM Vulnerabilities

pip LLM Inference

AI Threat Alert tracks 115 known vulnerabilities in vLLM, 12 rated critical — an AI/ML llm inference in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
61
Risk Score
115
Total CVEs
12
Critical
pip
Ecosystem
Sep 24, 2026
Last CVE
26%
Patch Rate
47d
Avg Time to Patch
92,736 stars 22,697 forks 8,318 issues 95 dependents Last push Sep 27, 2026
View on GitHub

Known Vulnerabilities (115 total, page 3 of 5)

Severity CVE ID Summary CVSS Published
HIGH CVE-2025-71379 vLLM: ReDoS via crafted API input causes DoS 7.5 Jun 20, 2026 MEDIUM CVE-2026-12706 FFmpeg RASC: UAF in decoder crashes AI inference containers 6.5 Jun 19, 2026 MEDIUM CVE-2026-54235 vLLM: NaN/Inf bypass crashes GPU inference workers 6.5 Jun 17, 2026 MEDIUM GHSA-8jr5-v98p-w75m vllm: EXIF/tRNS preprocessing gap enables adversarial input 4.8 Jun 17, 2026 HIGH CVE-2026-53923 vLLM: integer truncation leaks GPU memory cross-tenant 7.5 Jun 17, 2026 MEDIUM CVE-2026-54236 vLLM: heap address leak enables ASLR bypass 5.3 Jun 17, 2026 MEDIUM CVE-2026-54233 vLLM: decompression bomb OOM via audio endpoint 6.5 Jun 17, 2026 MEDIUM CVE-2026-12491 vLLM: image metadata mishandling corrupts multimodal inputs 4.8 Jun 17, 2026 HIGH CVE-2026-41523 vLLM: assert bypass → RCE via poisoned HuggingFace model 7.5 Jun 16, 2026 CRITICAL CVE-2026-48746 vllm: auth bypass exposes OpenAI inference API 9.1 Jun 16, 2026 HIGH CVE-2026-5201 gdk-pixbuf: JPEG heap overflow crashes vLLM inference 7.5 Mar 31, 2026 HIGH CVE-2026-4111 libarchive: infinite loop DoS in RAR5 decompression 7.5 Mar 13, 2026 MEDIUM CVE-2025-14831 GnuTLS: TLS cert parsing DoS hits vllm inference 5.3 Feb 9, 2026 HIGH CVE-2023-52356 libtiff: heap overflow DoS in vLLM inference via TIFF input 7.5 Jan 25, 2024 HIGH CVE-2026-5121 libarchive: integer overflow in zisofs hits vllm containers 7.5 Mar 30, 2026 HIGH CVE-2026-4424 libarchive: RAR heap OOB read leaks memory in vLLM stacks 7.5 Mar 19, 2026 LOW CVE-2026-10813 LMCache: weak hash enables KV cache integrity bypass 3.6 Jun 4, 2026 HIGH CVE-2026-5497 vLLM: unauthenticated OOM DoS via video frame parsing 7.5 Jun 11, 2026 MEDIUM CVE-2026-47155 vLLM: revision pin bypass loads unreviewed artifacts 6.5 Jun 10, 2026 UNKNOWN CVE-2026-4944 vllm: trust_remote_code bypass enables RCE via HuggingFace -- May 28, 2026 MEDIUM CVE-2026-9540 vllm: unauthenticated DoS in OpenAI-compatible serving path 5.3 May 26, 2026 MEDIUM CVE-2026-44223 vLLM: speculative decoding DoS via penalty params 6.5 May 6, 2026 MEDIUM CVE-2026-44222 vLLM: token injection DoS via multimodal placeholders 6.5 May 5, 2026 MEDIUM CVE-2026-7141 vllm: uninitialized KV cache memory leaks inference data 5.6 Apr 27, 2026 MEDIUM CVE-2026-34753 vLLM: SSRF in batch API exposes cloud metadata endpoints 5.4 Apr 3, 2026

Showing 51–75 of 115

Frequently asked questions

What is vLLM?

vLLM is an AI/ML llm inference tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does vLLM have?

vLLM has 115 known CVEs, 12 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is vLLM distributed in?

vLLM is distributed via the pip ecosystem and categorized as llm inference.

Where does the vLLM vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of vLLM?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor vLLM in your stack

Get instant alerts when new vulnerabilities affect vLLM. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring