Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-ph3r-5jfg-f84f
  • PyPI/vllm
vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core 7 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-935w-9g4m-p28p
  • PyPI/vllm
vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle 7 hours ago
  • Fix available
  • Severity - 3.1 (Low)
GHSA-x6mc-67gf-chw4
  • PyPI/vllm
vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach 8 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-58v5-2m8f-94pr
  • PyPI/vllm
vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion 8 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-ph72-cqr5-qpp7
  • PyPI/vllm
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features 8 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-85xf-c7hm-whqw
  • PyPI/vllm
vLLM: Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service (3 sites) 8 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-2phq-3phc-84px
  • PyPI/vllm
vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank` 8 hours ago
  • Fix available
  • Severity - 4.2 (Medium)
GHSA-2823-qmq8-rwvj
  • PyPI/vllm
vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service 8 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-4178
  • PyPI/vllm
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation 4 days ago
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-4179
  • PyPI/vllm
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions 4 days ago
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-4008
  • PyPI/vllm
See record for full details 21 Sep
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-4007
  • PyPI/vllm
See record for full details 21 Sep
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2026-4006
  • PyPI/vllm
See record for full details 21 Sep
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-4005
  • PyPI/vllm
See record for full details 21 Sep
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-4004
  • PyPI/vllm
See record for full details 21 Sep
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-4000
  • PyPI/vllm
See record for full details 19 Sep
  • Fix available
  • Severity - 4.3 (Medium)