Technology · PyPI
vllm (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 66 vulnerabilities in vllm (PyPI): 0 in the last 7 days and 19 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-90553, was published on 12 September 2026.
- Last 7 days
- 0
- Last 90 days
- 19
- Critical, all time
- 4
- Exploited in the wild
- 0
Latest vllm (PyPI) vulnerabilities
- CVE-2026-90553: vLLM LlavaOnevision2 processor remote code execution via trust_remote_code bypasshighCVSS 7.8EPSS 0.3%
- CVE-2026-73560: vLLM SSRF and arbitrary file read in MiMoV2OmniMultiModalProcessormediumCVSS 6.5EPSS 0.4%
- CVE-2026-73558: vLLM integer overflow in kernel causing cross-user data leakmediumCVSS 5.3EPSS 0.4%
- CVE-2026-73557: vLLM concurrent prompt-embedding guard bypassmediumCVSS 4EPSS 0.4%
- CVE-2026-73556: vLLM ReDoS in lm-format-enforcer backend regex parsingmediumCVSS 5.3EPSS 0.5%
- CVE-2026-73555: vLLM information disclosure via validation error messagesmediumCVSS 5.3EPSS 0.4%
- CVE-2026-71486: vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and…mediumCVSS 4.3EPSS 0.5%
- CVE-2026-73559: vLLM completion prompt lists DoSmediumCVSS 6.5EPSS 0.5%
- CVE-2025-6242: PYSEC-2026-2011 - vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` classlowCVSS 3.1EPSS 0.3%
- CVE-2025-61620: PYSEC-2026-2013 - vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible ServerlowCVSS 3.1
- CVE-2025-9141: PYSEC-2026-2014 - vLLM has remote code execution vulnerability in the tool call parser for Qwen3-CoderlowCVSS 3.1
- CVE-2024-8768: PYSEC-2026-2024 - vLLM denial of service vulnerabilitylowCVSS 3.1EPSS 0.7%
- CVE-2024-8939: PYSEC-2026-2025 - vLLM Denial of Service via the best_of parameterlowCVSS 3.1EPSS 0.2%
- CVE-2026-55574: vLLM ReDoS in structured_outputs.regex API parameterhighCVSS 7.5EPSS 0.6%
- CVE-2026-55514: vLLM denial of service via reachable assertion in M-RoPE modelshighCVSS 4EPSS 0.7%
- CVE-2026-54234: vLLM denial of service via invalid recovered token in speculative decodinghighCVSS 7.5EPSS 0.6%
- CVE-2026-55646: vLLM resource exhaustion in speech-to-text audio upload routesmediumCVSS 6.5EPSS 0.5%
- CVE-2024-11041: PYSEC-2026-566 - vLLM Deserialization of Untrusted Data vulnerabilitylowCVSS 3EPSS 1.6%
- CVE-2024-9052: PYSEC-2026-568 - vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_objectlowCVSS 3
- CVE-2026-54236: vLLM information disclosure via unsanitized error messages in Anthropic and STT endpointsmediumCVSS 5.3EPSS 0.9%
- CVE-2026-54235: vLLM improper input validation of non-finite floats in sampling parametersmediumCVSS 4EPSS 0.4%
- CVE-2026-54233: vLLM denial of service via audio decompression bomb in transcriptions endpointmediumCVSS 6.5EPSS 0.4%
- CVE-2026-54232: vLLM dependency confusion in Dockerfile via flashinfer-jit-cachehighCVSS 8.8EPSS 0.6%
- CVE-2026-53923: vLLM information disclosure via integer truncation in GGUF kernelsmediumCVSS 4EPSS 0.5%
- CVE-2026-48746: vLLM authentication bypass in OpenAI API via Host header injectioncriticalCVSS 9.1EPSS 1.1%
Most severe vllm (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-22778: vLLM remote code execution via JPEG2000 heap overflow and ASLR bypasscriticalCVSS 9.8EPSS 3.8%
- CVE-2024-9053: vLLM remote code execution via pickle deserialization in AsyncEngineRPCServercriticalCVSS 9.8EPSS 1.4%
- CVE-2025-47277: vLLM remote code execution via unsafe deserialization in PyNcclPipecriticalCVSS 9.8EPSS 1.0%
- CVE-2026-48746: vLLM authentication bypass in OpenAI API via Host header injectioncriticalCVSS 9.1EPSS 1.1%
- CVE-2026-27893: vLLM remote code execution via hardcoded remote code trust in modelshighCVSS 8.8EPSS 1.8%
- CVE-2025-62164: vLLM unsafe deserialization in Completions API prompt embeddingshighCVSS 8.8EPSS 0.9%
- CVE-2026-22807: vLLM arbitrary code execution via auto_map dynamic module loadinghighCVSS 8.8EPSS 0.8%
- CVE-2026-56340: vLLM improper input validation in multimodal embeddingshighCVSS 8.8EPSS 0.6%
- CVE-2026-54232: vLLM dependency confusion in Dockerfile via flashinfer-jit-cachehighCVSS 8.8EPSS 0.6%
- CVE-2025-30165: vLLM RCE via unsafe pickle deserialization in V0 enginehighCVSS 8EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 2 | 0 | |
| 6 Jul 2026 | 9 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 1 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 3 | 0 | |
| 7 Sep 2026 | 3 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pypi-vllm.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "vllm (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/pypi-vllm, 27 September 2026.