Vllm-project
5 CVEs tracked since 2025. Since May 2025, none of them reached CISA KEV.
Vllm-project CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-05 | 5 | 0 |
Products
The products that kept showing up in Vllm-project's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 14 most recently published vulnerabilities affecting Vllm-project.
- CVE-2026-25960SSRF Protection Bypass in vLLM7.1
- CVE-2025-62372vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs6.5
- CVE-2025-62426vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`6.5
- CVE-2025-62164VLLM deserialization vulnerability leading to DoS and potential RCE8.8
- CVE-2025-59425vLLM vulnerable to timing attack at bearer auth7.5
- CVE-2025-48956vLLM API endpoints vulnerable to Denial of Service Attacks7.5
- CVE-2025-48944vLLM Tool Schema allows DoS via Malformed pattern and type Fields6.5
- CVE-2025-48943vLLM allows clients to crash the openai server with invalid regex6.5
- CVE-2025-48942vLLM DOS: Remotely kill vllm over http with invalid JSON schema6.5
- CVE-2025-48887vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`6.5
- CVE-2025-46722vLLM has a Weakness in MultiModalHasher Image Hashing Implementation4.2
- CVE-2025-46570vLLM’s Chunk-Based Prefix Caching Vulnerable to Potential Timing Side-Channel2.6
- CVE-2025-47277vLLM Allows Remote Code Execution via PyNcclPipe Communication Service9.8
- CVE-2025-46560vLLM phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service6.5
The record
- Peak rank
- #162 in May 2025
- Busiest month shown
- May 2025, 5 CVEs
- Months with a KEV entry
- 0 since May 2025
- Monthly snapshots
- 1 since 2025