Known Vulnerabilities for products from Vllm
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Vllm".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-103241 json | Not Provided | 2026-09-30 | 2026-10-02 | |
| CVE-2026-100654 json | Not Provided | 2026-09-26 | 2026-09-30 | |
| CVE-2026-100653 json | Not Provided | 2026-09-26 | 2026-09-30 | |
| CVE-2026-100652 json | Not Provided | 2026-09-26 | 2026-09-28 | |
| CVE-2026-100651 json | Not Provided | 2026-09-26 | 2026-09-28 | |
| CVE-2026-100650 json | Not Provided | 2026-09-26 | 2026-09-30 | |
| CVE-2026-100649 json | Not Provided | 2026-09-26 | 2026-10-02 | |
| CVE-2026-100648 json | Not Provided | 2026-09-26 | 2026-09-28 | |
| CVE-2026-100647 json | Not Provided | 2026-09-26 | 2026-09-28 | |
| CVE-2026-94627 json | vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests s... | Not Provided | 2026-09-21 | 2026-09-29 |
| CVE-2026-94626 json | vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, ... | Not Provided | 2026-09-21 | 2026-09-29 |
| CVE-2026-94625 json | vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ... | Not Provided | 2026-09-21 | 2026-09-29 |
| CVE-2026-94624 json | vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured wi... | Not Provided | 2026-09-21 | 2026-09-29 |
| CVE-2026-94623 json | vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fai... | Not Provided | 2026-09-21 | 2026-09-29 |
| CVE-2026-94622 json | vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/... | Not Provided | 2026-09-21 | 2026-09-29 |
| CVE-2026-93989 json | vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in Samplin... | Not Provided | 2026-09-19 | 2026-09-28 |
| CVE-2026-93841 json | vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index th... | Not Provided | 2026-09-18 | 2026-09-28 |
| CVE-2026-93840 json | vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParam... | Not Provided | 2026-09-18 | 2026-09-28 |
| CVE-2026-93592 json | vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allow... | Not Provided | 2026-09-18 | 2026-09-28 |
| CVE-2026-93436 json | vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggr... | Not Provided | 2026-09-17 | 2026-09-28 |