Security: vllm-project/vllm
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
vLLM Unauthenticated Requests Exploit DeepStream Backend Confusion for DoSGHSA-cqm8-jxg6-fqfq published
Aug 11, 2026 by jperezdealgabaModerate -
Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt partsGHSA-pr7f-p5mw-fc87 published
Jul 27, 2026 by jperezdealgabaModerate -
Completion prompt lists fan out into unbounded engine requestsGHSA-87x5-vmc3-756j published
Jul 27, 2026 by jperezdealgabaModerate -
ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2mGHSA-48jh-3gj7-fg8v published
Jul 27, 2026 by jperezdealgabaModerate -
Derender endpoints decode caller-supplied GenerateResponse token IDs without output boundsGHSA-8737-qx52-hjff published
Jul 27, 2026 by jperezdealgabaModerate -
Unauthenticated audio decompression-bomb DoS in /v1/chat/completions: VLLM_MAX_AUDIO_DECODE_DURATION_S guard not wired into the chat audio path (sibling of CVE-2026-5497)GHSA-hcwq-8wjf-3gcr published
Aug 23, 2026 by jperezdealgabaModerate -
Speech-to-text upload size limit is enforced after full UploadFile readGHSA-v82g-2437-67m2 published
Jul 2, 2026 by jperezdealgabaModerate -
DoS caused by sending `/v1/completions` with prompt embeds payload with models that use M-RoPEGHSA-33cg-gxv8-3p8g published
Jul 2, 2026 by jperezdealgabaModerate -
Cross-User Data Leak VulnerabilityGHSA-7m6h-x95x-82q5 published
Aug 11, 2026 by jperezdealgabaModerate -
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router (CWE-532)GHSA-hgg8-fqqc-vfmw published
Jun 11, 2026 by jperezdealgabaModerate