Vulnerabilidades en vllm-project

79 resultados
Análisis Vexday

O vllm-project apresenta volume moderado de vulnerabilidades (51 CVEs) com concentração recente: 18 divulgadas nos últimos 90 dias. A fraqueza dominante (CWE-502 - Desserialização de dados não confiáveis) afeta 7 casos críticos, porém nenhuma vulnerabilidade está sob exploração ativa documentada (KEV). O risco é significativo pela cadência de descobertas recentes e pela natureza das falhas de desserialização, que tipicamente permitem execução remota de código.

CVE-2026-90878MEDIUMvllm-project vLLM Jinja Template Rendering completions resource consumptionEPSS 0.5%CVE-2026-73556MEDIUMvLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of CVE-2026-55574EPSS 0.5%CVE-2026-94625MEDIUMvLLM through 0.29.0 Resource Exhaustion via Ownerless Mooncake Transfer PlaceholdersEPSS 0.5%CVE-2026-92365MEDIUMvllm-project vllm thinking_budget_state.py algorithmic complexityEPSS 0.5%CVE-2026-90555HIGHvLLM before 0.28.0 Denial of Service via Audio HeaderEPSS 0.5%CVE-2026-55646MEDIUMvLLM speech-to-text endpoints allocate full upload before enforcing the audio file-size limitEPSS 0.5%CVE-2025-48944MEDIUMvLLM Tool Schema allows DoS via Malformed pattern and type FieldsEPSS 0.5%CVE-2026-93592HIGHvLLM before 0.28.0 Denial of Service via negative token IDEPSS 0.5%CVE-2025-48887MEDIUMvLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`EPSS 0.5%CVE-2025-46560MEDIUMvLLM phi4mm: Quadratic Time Complexity in Input Token Processing​ leads to denial of serviceEPSS 0.5%CVE-2026-53923MEDIUMvLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overflowEPSS 0.5%CVE-2025-30165HIGHRemote Code Execution Vulnerability in vLLM Multi-Node Cluster ConfigurationEPSS 0.5%CVE-2026-34760MEDIUMvLLM: Downmix Implementation Differences as Attack Vectors Against Audio AI ModelsEPSS 0.5%CVE-2025-48943MEDIUMvLLM allows clients to crash the openai server with invalid regexEPSS 0.5%CVE-2026-71486MEDIUMvLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output boundsEPSS 0.5%CVE-2025-29770MEDIUMvLLM denial of service via outlines unbounded cache on diskEPSS 0.5%CVE-2026-44222MEDIUMvLLM: Remote DoS via Special-Token PlaceholdersEPSS 0.5%CVE-2026-54235MEDIUMvLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernelsEPSS 0.4%CVE-2026-22773MEDIUMvLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensionsEPSS 0.4%CVE-2026-73560MEDIUMvLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protectionsEPSS 0.4%