vllm
PyPI54 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting vllmpage 2 of 2
- CVE-2026-55574HIGHCVSS 7.5EG 7.5✓ Fixed in 0.24.02026-07-06
vulnerable: 0.0.1 ... 0.9.2 (89 versions)
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular expression string directly to the grammar compiler backends wi…
- CVE-2026-55646MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.24.02026-07-06
vulnerable: 0.22.0, 0.22.1, 0.23.0
vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions and /v1/audio/translations routes call request.file.read() to fully materialize an uploaded audio file into memory befor…
- CVE-2026-56340HIGHCVSS 7.5EG 8.8✓ Fixed in 0.13.02026-06-20
vulnerable: 0.10.2, 0.11.0, 0.11.1, 0.11.2, 0.12.0
vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests with malfo…
- CVE-2026-7141MEDIUMCVSS 5.6EG 5.6✓ Fixed in 0.19.12026-04-27
vulnerable: 0.0.1 ... 0.9.2 (81 versions)
A vulnerability was found in vllm up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v1/kv_cache_interface.py of the component KV Block Handler. Performing a manipulation results in uninitialized resource.…
Check whether vllm is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for vllm CVEs against the assets you own.
Start Free Scan →