CVE Tools

Vllm

99 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Vllm, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Vllm CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Vllm CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-011
2025-021
2025-034
2025-045
2025-059
2025-060
2025-070
2025-082
2025-090
2025-103
2025-113
2025-121
2026-014
2026-021
2026-032
2026-045
2026-053
2026-0613
2026-074
2026-088
2026-0928

Severity

How the 99 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical78%
  • High2831%
  • Medium4954%
  • Low78%

Latest CVEs

The 15 most recently published vulnerabilities affecting Vllm.

  1. CVE-2026-100654vLLM before 0.29.0 Denial of Service via out-of-range stop_token_ids6.5
  2. CVE-2026-100653vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation6.5
  3. CVE-2026-100651vllm before 0.29.0 Denial of Service via Decoder Prompt Length Bypass6.5
  4. CVE-2026-100652vLLM 0.22.0 through 0.23.0 Denial of Service via stop_token_ids5.9
  5. CVE-2026-100650vLLM before 0.29.0 Resource Exhaustion via Unbounded Media Materialization6.5
  6. CVE-2026-100649vLLM before 0.29.0 Resource Limit Bypass via Sampler Subclass3.7
  7. CVE-2026-100648vllm before 0.29.0 Uncontrolled Resource Consumption via Audio Decoding5.3
  8. CVE-2026-100647vLLM before 0.29.0 CPU Exhaustion via unbounded cache_salt5.3
  9. CVE-2026-94627vLLM through 0.29.0 GPU KV Cache Leak via Mooncake Transfer ID Collision7.5
  10. CVE-2026-94626vLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_size7.5
  11. CVE-2026-94625vLLM through 0.29.0 Resource Exhaustion via Ownerless Mooncake Transfer Placeholders5.3
  12. CVE-2026-94624vLLM through 0.29.0 Denial of Service via Unbounded P2P KV Offloading Sessions7.5
  13. CVE-2026-94623vLLM through 0.29.0 Denial of Service via NIXL Multi-Prompt Assertion Failure7.5
  14. CVE-2026-94622vLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer Metadata7.5
  15. CVE-2026-93989vLLM through 0.29.0 Cross-Request Logits Corruption via bad_words3.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store