Junglewise Threat Intelligence

CVE-2025-71379: vLLM ReDoS in multiple components including LoRA and OpenAI chat endpoint

CVE-2025-71379 · Severity: medium · CVSS 4.3 · Published 2026-06-20

Technologies: vLLM Project vllm. Vendors: vLLM Project.

Executive brief

vLLM is a high-throughput engine for serving large language models (LLMs). Multiple components within the software are vulnerable to a denial-of-service attack where specially crafted text inputs can cause the system to consume excessive CPU resources. This can lead to significant performance degradation or a complete service outage, preventing legitimate users from accessing the AI models.

Technical details

vLLM is vulnerable to Regular Expression Denial of Service (ReDoS) due to inefficient regex patterns susceptible to catastrophic backtracking (CWE-1333). Vulnerable patterns exist in 'vllm/lora/utils.py', the 'phi4mini' tool parser, and the OpenAI-compatible serving chat endpoint. An attacker with network access and low privileges can submit crafted inputs with nested or repeated structures to trigger exponential backtracking. This results in extreme CPU exhaustion and service unavailability. The issue is addressed in version 0.9.0 by implementing stricter input constraints and more efficient parsing logic.

Affected products

  • vLLM Project vLLM >= 0.6.3, < 0.9.0

Timeline

  • 2025-05-28: advisory: Initial GitHub Security Advisory published
  • 2026-06-20: disclosed: NVD and VulnCheck publication date
  • 2025-09-01: patched: Fixed in version 0.9.0

References