vLLM Vulnerabilities

pip LLM Inference

AI Threat Alert tracks 115 known vulnerabilities in vLLM, 12 rated critical — an AI/ML llm inference in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
61
Risk Score
115
Total CVEs
12
Critical
pip
Ecosystem
Sep 24, 2026
Last CVE
26%
Patch Rate
47d
Avg Time to Patch
92,736 stars 22,697 forks 8,318 issues 95 dependents Last push Sep 27, 2026
View on GitHub

Known Vulnerabilities (115 total, page 4 of 5)

Severity CVE ID Summary CVSS Published
MEDIUM CVE-2026-34755 vLLM: OOM DoS via unbounded video frame decoding 6.5 Apr 3, 2026 MEDIUM CVE-2026-34756 vLLM: DoS via unbounded n parameter causes OOM crash 6.5 Apr 3, 2026 HIGH CVE-2026-34760 vLLM: audio downmix mismatch enables adversarial input 7.1 Apr 2, 2026 HIGH CVE-2026-27893 vLLM: trust_remote_code bypass enables RCE 8.8 Mar 27, 2026 CRITICAL CVE-2024-9052 vLLM: RCE via pickle deserialization in distributed API 9.8 Mar 20, 2025 MEDIUM GHSA-hf3c-wxg2-49q9 vLLM: DoS via unbounded XGrammar schema cache 6.5 Apr 15, 2025 CRITICAL GHSA-ggpf-24jw-3fcw vLLM: RCE via malicious model, PyTorch < 2.6 bypass 9.8 Apr 23, 2025 MEDIUM GHSA-j828-28rj-hfhp vllm: ReDoS in inference endpoints enables DoS 4.3 May 28, 2025 HIGH CVE-2025-9141 vLLM: RCE via eval() in Qwen3 Coder tool parser 8.8 Aug 21, 2025 MEDIUM CVE-2025-61620 vllm: DoS via Jinja template injection in chat API 6.5 Oct 7, 2025 HIGH GHSA-mcmc-2m55-j8jj vllm: Input Validation flaw enables exploitation 8.8 Jan 8, 2026 CRITICAL CVE-2026-25960 vllm: SSRF allows internal network access 9.8 Mar 9, 2026 CRITICAL CVE-2026-22778 vllm: security flaw enables exploitation 9.8 Feb 2, 2026 HIGH CVE-2026-24779 vllm: SSRF allows internal network access 7.1 Jan 27, 2026 CRITICAL CVE-2026-22807 vllm: Code Injection enables RCE 9.8 Jan 21, 2026 HIGH CVE-2026-22773 vllm: Resource Exhaustion enables DoS 7.5 Jan 10, 2026 HIGH CVE-2025-66448 vllm: Code Injection enables RCE 8.8 Dec 1, 2025 MEDIUM CVE-2025-62426 vllm: Resource Exhaustion enables DoS 6.5 Nov 21, 2025 MEDIUM CVE-2025-62372 vllm: security flaw enables exploitation 6.5 Nov 21, 2025 HIGH CVE-2025-62164 vllm: Input Validation flaw enables exploitation 8.8 Nov 21, 2025 HIGH CVE-2025-6242 vLLM: SSRF in media loader exposes internal network 7.1 Oct 7, 2025 HIGH CVE-2025-59425 vLLM: timing attack enables API key bypass 7.5 Oct 7, 2025 HIGH CVE-2025-48956 vLLM: unauthenticated DoS via oversized HTTP header 7.5 Aug 21, 2025 MEDIUM CVE-2025-48944 vLLM: input validation DoS crashes inference worker 6.5 May 30, 2025 MEDIUM CVE-2025-48943 vLLM: ReDoS crashes inference server via malformed regex 6.5 May 30, 2025

Showing 76–100 of 115

Frequently asked questions

What is vLLM?

vLLM is an AI/ML llm inference tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does vLLM have?

vLLM has 115 known CVEs, 12 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is vLLM distributed in?

vLLM is distributed via the pip ecosystem and categorized as llm inference.

Where does the vLLM vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of vLLM?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor vLLM in your stack

Get instant alerts when new vulnerabilities affect vLLM. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring