vllm-project vLLM
29 known vulnerabilities in vllm-project vLLM, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-103241 CVSS 5.5 medium A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file…
- CVE-2026-100654 CVSS 7.1 high vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/chat/completions…
- CVE-2026-100653 CVSS 8.3 high vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-supplied model…
- CVE-2026-100652 CVSS 8.2 high vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC frontends, allowing…
- CVE-2026-100651 CVSS 7.1 high vLLM before 0.29.0 fails to enforce decoder prompt-length validation on the disaggregated serving endpoint /inference/v1/generate. When…
- CVE-2026-100650 CVSS 7.1 high vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls (the…
- CVE-2026-100649 CVSS 6.3 medium vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler subclass shadowing…
- CVE-2026-100648 CVSS 6.9 medium vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing unauthenticated…
- CVE-2026-100647 CVSS 6.9 medium vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-compatible and…
- CVE-2026-94627 CVSS 8.7 high vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single…
- CVE-2026-94626 CVSS 8.7 high vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing…
- CVE-2026-94625 CVSS 6.9 medium vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless…
- CVE-2026-94624 CVSS 8.7 high vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with…
- CVE-2026-94623 CVSS 8.7 high vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to…
- CVE-2026-94622 CVSS 8.7 high vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode…
- CVE-2026-93989 CVSS 2.3 low vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in…
- CVE-2026-93841 CVSS 6.3 medium vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty…
- CVE-2026-93840 CVSS 6.3 medium vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in…
- CVE-2026-93592 CVSS 8.7 high vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing…
- CVE-2026-93436 CVSS 8.7 high vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated…
- CVE-2026-69147 CVSS 6.5 medium vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can…
- CVE-2026-57173 CVSS 6.5 medium vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions…
- CVE-2026-92365 CVSS 5.3 medium A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file…
- CVE-2026-92220 CVSS 6.9 medium A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function…
- CVE-2026-90878 CVSS 2.1 low A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the…
- CVE-2026-90713 CVSS 1.9 low A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the…
- CVE-2026-90555 CVSS 7.1 high vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to…
- CVE-2026-90554 CVSS 6.9 medium vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for…
- CVE-2026-90553 CVSS 8.5 high vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the…