Vulnerabilidades em vllm-project
79 resultadosAnálise Vexday
O vllm-project apresenta volume moderado de vulnerabilidades (51 CVEs) com concentração recente: 18 divulgadas nos últimos 90 dias. A fraqueza dominante (CWE-502 - Desserialização de dados não confiáveis) afeta 7 casos críticos, porém nenhuma vulnerabilidade está sob exploração ativa documentada (KEV). O risco é significativo pela cadência de descobertas recentes e pela natureza das falhas de desserialização, que tipicamente permitem execução remota de código.
CVE-2025-59425HIGHvLLM vulnerable to timing attack at bearer authEPSS 0.6%CVE-2026-54232HIGHvLLM: Dependency Confusion Vulnerability in vLLM DockerfileEPSS 0.6%CVE-2025-48956HIGHvLLM API endpoints vulnerable to Denial of Service AttacksEPSS 0.6%CVE-2026-24779HIGHvLLM vulnerable to Server-Side Request Forgery (SSRF) in `MediaConnector`EPSS 0.5%CVE-2026-25960HIGHSSRF Protection Bypass in vLLMEPSS 0.5%CVE-2025-48942MEDIUMvLLM DOS: Remotely kill vllm over http with invalid JSON schemaEPSS 0.5%CVE-2026-93436HIGHvLLM through 0.29.0 Memory Exhaustion via Rejected RequestsEPSS 0.5%CVE-2026-5497HIGHUnbounded Frame Count in video/jpeg Base64 Data URL Processing Leads to OOM DoS in vllm-project/vllmEPSS 0.5%CVE-2026-92220MEDIUMvllm-project vLLM MoRIIO Acknowledgement moriio_connector.py MoRIIOWrapper._handle_release_message resource consumptionEPSS 0.5%CVE-2026-55646MEDIUMvLLM speech-to-text endpoints allocate full upload before enforcing the audio file-size limitEPSS 0.5%CVE-2025-48944MEDIUMvLLM Tool Schema allows DoS via Malformed pattern and type FieldsEPSS 0.5%CVE-2025-48887MEDIUMvLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`EPSS 0.5%CVE-2025-46560MEDIUMvLLM phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of serviceEPSS 0.5%CVE-2026-53923MEDIUMvLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overflowEPSS 0.5%CVE-2025-30165HIGHRemote Code Execution Vulnerability in vLLM Multi-Node Cluster ConfigurationEPSS 0.5%CVE-2025-48943MEDIUMvLLM allows clients to crash the openai server with invalid regexEPSS 0.5%CVE-2026-73559MEDIUMvLLM: Completion prompt lists fan out into unbounded engine requestsEPSS 0.5%CVE-2026-34755MEDIUMvLLM Affected by Denial of Service via Unbounded Frame Count in video/jpeg Base64 ProcessingEPSS 0.5%CVE-2025-29770MEDIUMvLLM denial of service via outlines unbounded cache on diskEPSS 0.5%CVE-2026-69147MEDIUMvLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservationEPSS 0.5%