pkg:PyPI/vllm
共 55 筆 CVECRITICAL10HIGH14MEDIUM27LOW4
✅ 檢查你的版本
所有已知漏洞
- >= 0.6.5, < 0.8.5
- from 0, < a5450f11c95847cf51a17207af9a3ca5ab569b2c | >= 0.6.5, < 0.8.5
- >= 0.8.3, < 0.14.1
- >= 0.6.5, < 0.8.5
- CRITICAL9.8CVE-2024-9053vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypointsfrom 0, <= 0.6.0
- CRITICAL9.8CVE-2024-9053vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypointsfrom 0, <= 0.6.0
- CRITICAL9.8CVE-2024-9052vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_objectfrom 0, <= 0.8.1
- from 0, <= 0.6.2
- >= 0.6.5, < 0.8.0
- from 0, < 288ca110f68d23909728627d3100e5a8db820aa2 | >= 0.6.5, < 0.8.0
- HIGH8.8CVE-2026-27893vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out>= 0.10.1, < 0.18.0
- HIGH8.8CVE-2026-22807vLLM affected by RCE via auto_map dynamic module loading during model initialization>= 0.10.1, < 0.14.0
- >= 0.10.2, < 0.11.1
- HIGH8.8CVE-2025-9141vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder>= 0.10.0, < 0.10.1.1
- >= 0.5.2, < 0.10.0
- from 0, < 0.11.0
- >= 0.1.0, < 0.10.1.1
- >= 0.5.2, < 0.8.5
- from 0, < d3d6bb13fb62da3234addf6574922a4ec0513d04 | from 0, < 0.7.0
- from 0, < 0.7.0
- from 0, < 0.5.5
- from 0, < 0.14.1
- from 0, < 0.11.1
- HIGH7.1CVE-2025-6242vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class>= 0.5.0, < 0.11.0
- MEDIUM6.5CVE-2026-44223vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters>= 0.18.0, < 0.20.0
- MEDIUM6.5CVE-2026-44223vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters>= 0.18.0, < 0.20.0
- >= 0.6.1, < 0.20.0
- MEDIUM6.5CVE-2026-34755vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing>= 0.7.0, < 0.19.0
- MEDIUM6.5CVE-2026-34755vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing>= 0.7.0, < 0.19.0
- MEDIUM6.5CVE-2026-34756vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server>= 0.1.0, < 0.19.0
- MEDIUM6.5CVE-2026-22773vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions>= 0.6.4, < 0.12.0
- MEDIUM6.5CVE-2026-22773vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions>= 0.6.4, < 0.12.0
- MEDIUM6.5CVE-2025-62426vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`>= 0.5.5, < 0.11.1
- >= 0.5.5, < 0.11.1
- MEDIUM6.5CVE-2025-61620vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server>= 0.5.1, < 0.11.0
- >= 0.8.0, < 0.9.0
- from 0, < 08bf7840780980c7568c573c70a6a8db94fd45ff | >= 0.8.0, < 0.9.0
- >= 0.8.0, < 0.9.0
- >= 0.8.0, < 0.9.0
- from 0, < 08bf7840780980c7568c573c70a6a8db94fd45ff | >= 0.8.0, < 0.9.0
- MEDIUM6.5CVE-2025-48887vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`>= 0.6.4, < 0.9.0
- MEDIUM6.5CVE-2025-48887vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`from 0, < 4fc1bf813ad80172c1db31264beaef7d93fe0601 | >= 0.6.4, < 0.9.0
- MEDIUM6.5CVE-2025-46560phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service>= 0.8.0, < 0.8.5
- from 0, < 0.8.0
- from 0, < 0.8.0
- from 0, <= 0.5.0.post1
- from 0, < 0.19.1
- >= 0.16.0, < 0.19.0
- >= 0.15.1, < 0.17.0
- >= 0.7.0, < 0.9.0
- from 0, < 99404f53c72965b41558aceb1bc2380875f5d848 | from 0, < 0.9.0
- LOW2.6CVE-2025-46570Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Cachingfrom 0, < 77073c77bc2006eb80ea6d5128f076f5e6c6f54f | from 0, < 0.9.0
- LOW2.6CVE-2025-46570Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Cachingfrom 0, < 0.9.0
- LOW2.6CVE-2025-25183vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cachefrom 0, < 432117cd1f59c76d97da2eaff55a7d758301dbc7 | from 0, < 0.7.2
- LOW2.6CVE-2025-25183vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cachefrom 0, < 0.7.2