Vulnerabilidades em vllm-project
79 resultadosAnálise Vexday
O vllm-project apresenta volume moderado de vulnerabilidades (51 CVEs) com concentração recente: 18 divulgadas nos últimos 90 dias. A fraqueza dominante (CWE-502 - Desserialização de dados não confiáveis) afeta 7 casos críticos, porém nenhuma vulnerabilidade está sob exploração ativa documentada (KEV). O risco é significativo pela cadência de descobertas recentes e pela natureza das falhas de desserialização, que tipicamente permitem execução remota de código.
CVE-2026-54235MEDIUMvLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernelsEPSS 0.4%CVE-2026-22773MEDIUMvLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensionsEPSS 0.4%CVE-2026-94623HIGHvLLM through 0.29.0 Denial of Service via NIXL Multi-Prompt Assertion FailureEPSS 0.4%CVE-2026-94622HIGHvLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer MetadataEPSS 0.4%CVE-2026-94624HIGHvLLM through 0.29.0 Denial of Service via Unbounded P2P KV Offloading SessionsEPSS 0.4%CVE-2026-94627HIGHvLLM through 0.29.0 GPU KV Cache Leak via Mooncake Transfer ID CollisionEPSS 0.4%CVE-2026-94626HIGHvLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_sizeEPSS 0.4%CVE-2026-9540MEDIUMvllm-project vllm OpenAI-compatible Serving Path denial of serviceEPSS 0.4%CVE-2026-54233MEDIUMvLLM: OOM Denial of Service via Audio Decompression BombEPSS 0.4%CVE-2026-34756MEDIUMvLLM Affected by Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API ServerEPSS 0.4%CVE-2026-44222MEDIUMvLLM: Remote DoS via Special-Token PlaceholdersEPSS 0.4%CVE-2026-92365MEDIUMvllm-project vllm thinking_budget_state.py algorithmic complexityEPSS 0.4%CVE-2025-62372HIGHvLLM vulnerable to DoS with incorrect shape of multimodal embedding inputsEPSS 0.4%CVE-2026-93592HIGHvLLM before 0.28.0 Denial of Service via negative token IDEPSS 0.4%CVE-2025-62426MEDIUMvLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`EPSS 0.4%CVE-2026-44223MEDIUMvLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parametersEPSS 0.4%CVE-2026-71486MEDIUMvLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output boundsEPSS 0.3%CVE-2026-78684MEDIUMvLLM before 0.27.0 Denial of Service via DeepStream BackendEPSS 0.3%CVE-2026-73558MEDIUMvLLM: Cross-User Data Leak VulnerabilityEPSS 0.3%CVE-2026-73560MEDIUMvLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protectionsEPSS 0.3%