Security: vllm-project/vllm
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router (CWE-532)GHSA-hgg8-fqqc-vfmw published
Jun 11, 2026 by jperezdealgabaModerate -
Dependency Confusion Vulnerability in vLLM DockerfileGHSA-jrf6-vqxq-pjv2 published
Jun 9, 2026 by russellbHigh -
Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processorsGHSA-3ww4-5jv9-j5gm published
Jun 10, 2026 by jperezdealgabaModerate -
extract_hidden_states speculative decoding crashes server on any request with penalty parametersGHSA-83vm-p52w-f9pw published
Apr 28, 2026 by russellbModerate -
temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernelsGHSA-7h4p-rffg-7823 published
Jun 11, 2026 by jperezdealgabaModerate -
OOM Denial of Service via Audio Decompression BombGHSA-6pr9-rp53-2pmc published
Jun 11, 2026 by jperezdealgabaModerate -
Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code ExecutionGHSA-q8gq-377p-jq3r published
Jun 14, 2026 by jperezdealgabaHigh -
GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant servingGHSA-5jv2-g5wq-cmr4 published
Jun 11, 2026 by jperezdealgabaModerate -
Denial of Service via Unbounded Frame Count in video/jpeg Base64 ProcessingGHSA-pq5c-rjhq-qp7p published
Apr 3, 2026 by russellbModerate -
Server-Side Request Forgery (SSRF) in `download_bytes_from_url `GHSA-pf3h-qjgv-vcpr published
Apr 3, 2026 by russellbModerate