Catalog / vLLM

vLLM security advisories

All 67 advisories vLLM has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
6761 carry a CVE
critical
5
high
18
medium
41
low
3
Fix in the archive
67of 67 matched to a release
Oldest
27 Jan 20251.6 years ago

Every advisory here is matched to the release in the archive that carries its fix. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
GHSA-3c86-2m5g-59q7high

LlavaOnevision2 processor loader executes attacker model code with `trust_remote_code=False` (inert `trust_remote_code` kwarg to `transformers.get_class_from_dynamic_module`) — RCE from a malicious model

CVE-2026-57173medium

Unauthenticated audio decompression-bomb DoS in /v1/chat/completions: VLLM_MAX_AUDIO_DECODE_DURATION_S guard not wired into the chat audio path (sibling of CVE-2026-5497)

GHSA-hcwq-8wjf-3gcrFixed in 0.24.0
CVE-2026-73560medium

SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

GHSA-4hhp-h66f-j5j7Fixed in 0.26.0
CVE-2026-73555low

Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

GHSA-hwrm-c4cx-rf4jFixed in 0.26.0
CVE-2026-71486medium

Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

GHSA-8737-qx52-hjffFixed in 0.26.0
CVE-2026-73556medium

ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m

GHSA-48jh-3gj7-fg8vFixed in 0.26.0
CVE-2026-73557medium

Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

GHSA-pr7f-p5mw-fc87Fixed in 0.26.0
CVE-2026-55574medium

ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends

GHSA-rwxx-mrjm-wc2mFixed in 0.24.0
CVE-2026-55514medium

DoS caused by sending `/v1/completions` with prompt embeds payload with models that use M-RoPE

GHSA-33cg-gxv8-3p8gFixed in 0.24.0
CVE-2026-41523high

Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution

GHSA-q8gq-377p-jq3rFixed in 0.22.0
CVE-2026-12491medium

vLLM image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

GHSA-8jr5-v98p-w75mFixed in 0.24.0
CVE-2026-53923medium

GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving

GHSA-5jv2-g5wq-cmr4Fixed in 0.24.0
CVE-2026-54235medium

temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels

GHSA-7h4p-rffg-7823Fixed in 0.24.0
CVE-2026-54236medium

vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router (CWE-532)

GHSA-hgg8-fqqc-vfmwFixed in 0.24.0
CVE-2026-47155medium

Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors

GHSA-3ww4-5jv9-j5gmFixed in 0.22.0
CVE-2026-44223medium

extract_hidden_states speculative decoding crashes server on any request with penalty parameters

GHSA-83vm-p52w-f9pwFixed in 0.20.0
CVE-2026-27893high

Hardcoded trust_remote_code=True in NemotronVL and KimiK25 bypasses user security opt-out

GHSA-7972-pg2x-xr59Fixed in 0.18.0
CVE-2025-62426medium

DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`

GHSA-69j4-grxj-j64pFixed in 0.11.1
CVE-2025-61620medium

Resource-Exhaustion (DoS) through chat_template / chat_template_kwargs in OpenAI-Compatible Server

GHSA-6fvq-23cw-5628Fixed in 0.11.0
CVE-2025-46570low

Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching

GHSA-4qjh-9fv9-r85rFixed in 0.9.0
CVE-2025-48887medium

Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`

GHSA-w6q7-j642-7c25Fixed in 0.9.0
CVE-2025-46560medium

phi4mm: Quadratic Time Complexity in Input Token Processing​ leads to denial of service

GHSA-vc6m-hm49-g9qgFixed in 0.8.5
CVE-2025-32434high

CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0

GHSA-ggpf-24jw-3fcwFixed in 0.8.0
CVE-2025-25183low

vLLM using built-in hash() from Python 3.12 leads to predictable hash collisions in vLLM prefix cache

GHSA-rm76-4mrf-v9r8Fixed in 0.7.2