Security: vllm-project/vllm
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Speech-to-text upload size limit is enforced after full UploadFile readGHSA-v82g-2437-67m2 published
Jul 2, 2026 by jperezdealgabaModerate -
DoS caused by sending `/v1/completions` with prompt embeds payload with models that use M-RoPEGHSA-33cg-gxv8-3p8g published
Jul 2, 2026 by jperezdealgabaModerate -
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router (CWE-532)GHSA-hgg8-fqqc-vfmw published
Jun 11, 2026 by jperezdealgabaModerate -
Dependency Confusion Vulnerability in vLLM DockerfileGHSA-jrf6-vqxq-pjv2 published
Jun 9, 2026 by russellbHigh -
Remote DoS in vLLM via Invalid Recovered Token ReinjectionGHSA-8wr5-jm2h-8r4f published
Jul 2, 2026 by jperezdealgabaHigh -
Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processorsGHSA-3ww4-5jv9-j5gm published
Jun 10, 2026 by jperezdealgabaModerate -
extract_hidden_states speculative decoding crashes server on any request with penalty parametersGHSA-83vm-p52w-f9pw published
Apr 28, 2026 by russellbModerate -
temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernelsGHSA-7h4p-rffg-7823 published
Jun 11, 2026 by jperezdealgabaModerate -
ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backendsGHSA-rwxx-mrjm-wc2m published
Jul 2, 2026 by jperezdealgabaModerate -
OOM Denial of Service via Audio Decompression BombGHSA-6pr9-rp53-2pmc published
Jun 11, 2026 by jperezdealgabaModerate