Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2184320
AlmaLinux
5857
Alpaquita
15521
Alpine
4589
Android
3674
Azure Linux
17131
BellSoft Hardened Containers
744
Bitnami
9212
Chainguard
1019778
CleanStart
3432
CRAN
14
crates.io
2710
Debian
67341
Echo
6542
GHC
3
GIT
106316
GitHub Actions
55
Go
9147
Hackage
32
Hex
351
Julia
1713
Linux
29368
Mageia
6200
Maven
6998
MinimOS
142693
npm
228436
NuGet
1860
opam
29
openEuler
8674
openSUSE
14325
OSS-Fuzz
4003
Packagist
7036
Pub
11
PyPI
25074
Red Hat
23028
Rocky Linux
4229
Root
19463
RubyGems
4709
SUSE
23039
SwiftURL
59
TuxCare
9207
Ubuntu
64326
VSCode
21
Wolfi
287370
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-8pw2-6jv3-mj5j
PyPI/vllm
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
2 days ago
Fix available
Severity - 6.5 (Medium)
GHSA-hcwq-8wjf-3gcr
PyPI/vllm
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
3 days ago
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-3985
PyPI/vllm
See record for full details
12 Sep
Fix available
Severity - 8.5 (High)
PYSEC-2026-3934
PyPI/vllm
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
10 Sep
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-3935
PyPI/vllm
vLLM: Cross-User Data Leak Vulnerability
10 Sep
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-3938
PyPI/vllm
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
10 Sep
Fix available
Severity - 6.3 (Medium)
PYSEC-2026-3933
PyPI/vllm
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
10 Sep
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-3937
PyPI/vllm
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
10 Sep
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-3936
PyPI/vllm
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
10 Sep
Fix available
Severity - 4.3 (Medium)
GHSA-4hhp-h66f-j5j7
PyPI/vllm
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
08 Sep
Fix available
Severity - 6.5 (Medium)
GHSA-7m6h-x95x-82q5
PyPI/vllm
vLLM: Cross-User Data Leak Vulnerability
08 Sep
Fix available
Severity - 5.3 (Medium)
GHSA-pr7f-p5mw-fc87
PyPI/vllm
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
04 Sep
Fix available
Severity - 6.3 (Medium)
GHSA-48jh-3gj7-fg8v
PyPI/vllm
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
04 Sep
Fix available
Severity - 5.3 (Medium)
GHSA-hwrm-c4cx-rf4j
PyPI/vllm
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
04 Sep
Fix available
Severity - 5.3 (Medium)
GHSA-8737-qx52-hjff
PyPI/vllm
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
04 Sep
Fix available
Severity - 4.3 (Medium)
PYSEC-2026-3704
PyPI/vllm
vLLM: Completion prompt lists fan out into unbounded engine requests
19 Aug
Fix available
Severity - 6.5 (Medium)
Load more...
PyPI - OSV