Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2198594
AlmaLinux
5919
Alpaquita
15755
Alpine
4608
Android
3674
Azure Linux
17638
BellSoft Hardened Containers
746
Bitnami
9290
Chainguard
1023658
CleanStart
3591
CRAN
14
crates.io
2732
Debian
68356
Echo
6717
GHC
3
GIT
108079
GitHub Actions
55
Go
9203
Hackage
32
Hex
361
Julia
1713
Linux
29974
Mageia
6227
Maven
7040
MinimOS
144270
npm
228732
NuGet
1869
opam
29
openEuler
8800
openSUSE
14455
OSS-Fuzz
4013
Packagist
7095
Pub
11
PyPI
25166
Red Hat
23331
Rocky Linux
4295
Root
19534
RubyGems
5326
SUSE
23081
SwiftURL
60
TuxCare
9490
Ubuntu
65370
VSCode
21
Wolfi
288261
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-8pw2-6jv3-mj5j
PyPI/vllm
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
17 Sep
Fix available
Severity - 6.5 (Medium)
GHSA-hcwq-8wjf-3gcr
PyPI/vllm
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
16 Sep
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-3985
PyPI/vllm
See record for full details
12 Sep
Fix available
Severity - 8.5 (High)
PYSEC-2026-3934
PyPI/vllm
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
10 Sep
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-3935
PyPI/vllm
vLLM: Cross-User Data Leak Vulnerability
10 Sep
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-3938
PyPI/vllm
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
10 Sep
Fix available
Severity - 6.3 (Medium)
PYSEC-2026-3933
PyPI/vllm
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
10 Sep
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-3937
PyPI/vllm
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
10 Sep
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-3936
PyPI/vllm
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
10 Sep
Fix available
Severity - 4.3 (Medium)
GHSA-4hhp-h66f-j5j7
PyPI/vllm
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
08 Sep
Fix available
Severity - 6.5 (Medium)
GHSA-7m6h-x95x-82q5
PyPI/vllm
vLLM: Cross-User Data Leak Vulnerability
08 Sep
Fix available
Severity - 5.3 (Medium)
GHSA-pr7f-p5mw-fc87
PyPI/vllm
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
04 Sep
Fix available
Severity - 6.3 (Medium)
GHSA-48jh-3gj7-fg8v
PyPI/vllm
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
04 Sep
Fix available
Severity - 5.3 (Medium)
GHSA-hwrm-c4cx-rf4j
PyPI/vllm
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
04 Sep
Fix available
Severity - 5.3 (Medium)
GHSA-8737-qx52-hjff
PyPI/vllm
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
04 Sep
Fix available
Severity - 4.3 (Medium)
PYSEC-2026-3704
PyPI/vllm
vLLM: Completion prompt lists fan out into unbounded engine requests
19 Aug
Fix available
Severity - 6.5 (Medium)
Load more...
PyPI - OSV