Vulnerabilidades en vllm-project

79 resultados
Análisis Vexday

O vllm-project apresenta volume moderado de vulnerabilidades (51 CVEs) com concentração recente: 18 divulgadas nos últimos 90 dias. A fraqueza dominante (CWE-502 - Desserialização de dados não confiáveis) afeta 7 casos críticos, porém nenhuma vulnerabilidade está sob exploração ativa documentada (KEV). O risco é significativo pela cadência de descobertas recentes e pela natureza das falhas de desserialização, que tipicamente permitem execução remota de código.

CVE-2026-44223MEDIUMvLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parametersEPSS 0.4%CVE-2026-54233MEDIUMvLLM: OOM Denial of Service via Audio Decompression BombEPSS 0.4%CVE-2026-73555MEDIUMvLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error MessagesEPSS 0.4%CVE-2026-93840MEDIUMvLLM before 0.29.0 Cross-Request Logits Corruption via allowed_token_idsEPSS 0.4%CVE-2026-73557MEDIUMvLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt partsEPSS 0.4%CVE-2026-73558MEDIUMvLLM: Cross-User Data Leak VulnerabilityEPSS 0.4%CVE-2026-93841MEDIUMvLLM through 0.29.0 Adjacent-Request Sampler State Corruption via Unvalidated Prompt Token IDsEPSS 0.4%CVE-2025-62372HIGHvLLM vulnerable to DoS with incorrect shape of multimodal embedding inputsEPSS 0.4%CVE-2025-62426MEDIUMvLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`EPSS 0.4%CVE-2026-93989LOWvLLM through 0.29.0 Cross-Request Logits Corruption via bad_wordsEPSS 0.3%CVE-2025-46722MEDIUMvLLM has a Weakness in MultiModalHasher Image Hashing ImplementationEPSS 0.3%CVE-2026-90553HIGHvLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processorEPSS 0.3%CVE-2026-34753MEDIUMvLLM affected by Server-Side Request Forgery (SSRF) in `download_bytes_from_url `EPSS 0.3%CVE-2025-46570LOWvLLM’s Chunk-Based Prefix Caching Vulnerable to Potential Timing Side-ChannelEPSS 0.3%CVE-2026-47155MEDIUMvLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processorsEPSS 0.2%CVE-2026-12491MEDIUMVllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectationsEPSS 0.2%CVE-2025-25183LOWvLLM using built-in hash() from Python 3.12 leads to predictable hash collisions in vLLM prefix cacheEPSS 0.2%CVE-2026-90554MEDIUMvLLM before 0.28.0 Denial of Service via audio extractionEPSS 0.2%CVE-2026-90713MEDIUMvllm-project vLLM tiktoken vocab File mod.rs new denial of serviceEPSS 0.2%