Vllm
99 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Vllm, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Vllm CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 1 |
| 2025-02 | 1 |
| 2025-03 | 4 |
| 2025-04 | 5 |
| 2025-05 | 9 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 2 |
| 2025-09 | 0 |
| 2025-10 | 3 |
| 2025-11 | 3 |
| 2025-12 | 1 |
| 2026-01 | 4 |
| 2026-02 | 1 |
| 2026-03 | 2 |
| 2026-04 | 5 |
| 2026-05 | 3 |
| 2026-06 | 13 |
| 2026-07 | 4 |
| 2026-08 | 8 |
| 2026-09 | 28 |
Severity
How the 99 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical7
- High28
- Medium49
- Low7
Latest CVEs
The 15 most recently published vulnerabilities affecting Vllm.
- CVE-2026-100654vLLM before 0.29.0 Denial of Service via out-of-range stop_token_ids6.5
- CVE-2026-100653vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation6.5
- CVE-2026-100651vllm before 0.29.0 Denial of Service via Decoder Prompt Length Bypass6.5
- CVE-2026-100652vLLM 0.22.0 through 0.23.0 Denial of Service via stop_token_ids5.9
- CVE-2026-100650vLLM before 0.29.0 Resource Exhaustion via Unbounded Media Materialization6.5
- CVE-2026-100649vLLM before 0.29.0 Resource Limit Bypass via Sampler Subclass3.7
- CVE-2026-100648vllm before 0.29.0 Uncontrolled Resource Consumption via Audio Decoding5.3
- CVE-2026-100647vLLM before 0.29.0 CPU Exhaustion via unbounded cache_salt5.3
- CVE-2026-94627vLLM through 0.29.0 GPU KV Cache Leak via Mooncake Transfer ID Collision7.5
- CVE-2026-94626vLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_size7.5
- CVE-2026-94625vLLM through 0.29.0 Resource Exhaustion via Ownerless Mooncake Transfer Placeholders5.3
- CVE-2026-94624vLLM through 0.29.0 Denial of Service via Unbounded P2P KV Offloading Sessions7.5
- CVE-2026-94623vLLM through 0.29.0 Denial of Service via NIXL Multi-Prompt Assertion Failure7.5
- CVE-2026-94622vLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer Metadata7.5
- CVE-2026-93989vLLM through 0.29.0 Cross-Request Logits Corruption via bad_words3.1
Product grouping is registry-driven, with AI assist and human review. How it works