{"schema_version":1,"title":"vllm (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 66 vulnerabilities in vllm (PyPI): 0 in the last 7 days and 19 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-90553, was published on 12 September 2026.","url":"https://junglewise.ai/threats/technologies/pypi-vllm","json_url":"https://junglewise.ai/threats/technologies/pypi-vllm.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pypi-vllm","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":18,"all_time":66,"critical":4,"exploited":0,"last_7_days":0,"last_30_days":6,"last_90_days":19,"last_365_days":49},"latest":[{"cve":"CVE-2026-90553","cvss":7.8,"epss":0.0031,"slug":"cve-2026-90553-vllm-llavaonevision2-processor-remote-code-execution-via-trust","title":"vLLM LlavaOnevision2 processor remote code execution via trust_remote_code bypass","severity":"high","exploited":false,"published_at":"2026-09-12T13:16:53.887+00:00","url":"https://junglewise.ai/threats/cve-2026-90553-vllm-llavaonevision2-processor-remote-code-execution-via-trust"},{"cve":"CVE-2026-73560","cvss":6.5,"epss":0.0044,"slug":"cve-2026-73560-vllm-ssrf-and-arbitrary-file-read-in","title":"vLLM SSRF and arbitrary file read in MiMoV2OmniMultiModalProcessor","severity":"medium","exploited":false,"published_at":"2026-09-08T20:42:00+00:00","url":"https://junglewise.ai/threats/cve-2026-73560-vllm-ssrf-and-arbitrary-file-read-in"},{"cve":"CVE-2026-73558","cvss":5.3,"epss":0.004,"slug":"cve-2026-73558-vllm-integer-overflow-in-kernel-causing-cross-user-data-leak","title":"vLLM integer overflow in kernel causing cross-user data leak","severity":"medium","exploited":false,"published_at":"2026-09-08T20:24:49+00:00","url":"https://junglewise.ai/threats/cve-2026-73558-vllm-integer-overflow-in-kernel-causing-cross-user-data-leak"},{"cve":"CVE-2026-73557","cvss":4,"epss":0.004,"slug":"cve-2026-73557-vllm-concurrent-prompt-embedding-guard-bypass","title":"vLLM concurrent prompt-embedding guard bypass","severity":"medium","exploited":false,"published_at":"2026-09-04T21:39:02+00:00","url":"https://junglewise.ai/threats/cve-2026-73557-vllm-concurrent-prompt-embedding-guard-bypass"},{"cve":"CVE-2026-73556","cvss":5.3,"epss":0.0052,"slug":"cve-2026-73556-vllm-redos-in-lm-format-enforcer-backend-regex-parsing","title":"vLLM ReDoS in lm-format-enforcer backend regex parsing","severity":"medium","exploited":false,"published_at":"2026-09-04T21:37:00+00:00","url":"https://junglewise.ai/threats/cve-2026-73556-vllm-redos-in-lm-format-enforcer-backend-regex-parsing"},{"cve":"CVE-2026-73555","cvss":5.3,"epss":0.0042,"slug":"cve-2026-73555-vllm-information-disclosure-via-validation-error-messages","title":"vLLM information disclosure via validation error messages","severity":"medium","exploited":false,"published_at":"2026-09-04T21:36:33+00:00","url":"https://junglewise.ai/threats/cve-2026-73555-vllm-information-disclosure-via-validation-error-messages"},{"cve":"CVE-2026-71486","cvss":4.3,"epss":0.0047,"slug":"cve-2026-71486-vllm-derender-endpoints-unbounded-token-decoding-dos","title":"vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/de","severity":"medium","exploited":false,"published_at":"2026-08-17T20:16:45.927+00:00","url":"https://junglewise.ai/threats/cve-2026-71486-vllm-derender-endpoints-unbounded-token-decoding-dos"},{"cve":"CVE-2026-73559","cvss":6.5,"epss":0.0055,"slug":"cve-2026-73559-vllm-completion-prompt-lists-dos","title":"vLLM completion prompt lists DoS","severity":"medium","exploited":false,"published_at":"2026-08-13T18:40:06+00:00","url":"https://junglewise.ai/threats/cve-2026-73559-vllm-completion-prompt-lists-dos"},{"cve":"CVE-2025-6242","cvss":3.1,"epss":0.0025,"slug":"cve-2025-6242-vllm-server-side-request-forgery-in-mediaconnector","title":"PYSEC-2026-2011 - vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:06.99247+00:00","url":"https://junglewise.ai/threats/cve-2025-6242-vllm-server-side-request-forgery-in-mediaconnector"},{"cve":"CVE-2025-61620","cvss":3.1,"slug":"cve-2025-61620-vllm-resource-exhaustion-dos-through-malicious-jinja-template-in","title":"PYSEC-2026-2013 - vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:06.869419+00:00","url":"https://junglewise.ai/threats/cve-2025-61620-vllm-resource-exhaustion-dos-through-malicious-jinja-template-in"},{"cve":"CVE-2025-9141","cvss":3.1,"slug":"cve-2025-9141-vllm-has-remote-code-execution-vulnerability-in-the-tool-call","title":"PYSEC-2026-2014 - vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:01.633632+00:00","url":"https://junglewise.ai/threats/cve-2025-9141-vllm-has-remote-code-execution-vulnerability-in-the-tool-call"},{"cve":"CVE-2024-8768","cvss":3.1,"epss":0.0068,"slug":"cve-2024-8768-vllm-denial-of-service-vulnerability","title":"PYSEC-2026-2024 - vLLM denial of service vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:41.726192+00:00","url":"https://junglewise.ai/threats/cve-2024-8768-vllm-denial-of-service-vulnerability"},{"cve":"CVE-2024-8939","cvss":3.1,"epss":0.0023,"slug":"cve-2024-8939-vllm-denial-of-service-via-the-best-of-parameter","title":"PYSEC-2026-2025 - vLLM Denial of Service via the best_of parameter","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:41.654363+00:00","url":"https://junglewise.ai/threats/cve-2024-8939-vllm-denial-of-service-via-the-best-of-parameter"},{"cve":"CVE-2026-55574","cvss":7.5,"epss":0.0058,"slug":"cve-2026-55574-vllm-redos-in-structured-outputs-regex-api-parameter","title":"vLLM ReDoS in structured_outputs.regex API parameter","severity":"high","exploited":false,"published_at":"2026-07-06T21:16:57.347+00:00","url":"https://junglewise.ai/threats/cve-2026-55574-vllm-redos-in-structured-outputs-regex-api-parameter"},{"cve":"CVE-2026-55514","cvss":4,"epss":0.0067,"slug":"cve-2026-55514-vllm-denial-of-service-via-reachable-assertion-in-m-rope-models","title":"vLLM denial of service via reachable assertion in M-RoPE models","severity":"high","exploited":false,"published_at":"2026-07-06T21:16:57.207+00:00","url":"https://junglewise.ai/threats/cve-2026-55514-vllm-denial-of-service-via-reachable-assertion-in-m-rope-models"},{"cve":"CVE-2026-54234","cvss":7.5,"epss":0.0062,"slug":"cve-2026-54234-vllm-denial-of-service-via-invalid-recovered-token-in-speculative","title":"vLLM denial of service via invalid recovered token in speculative decoding","severity":"high","exploited":false,"published_at":"2026-07-06T21:16:56.477+00:00","url":"https://junglewise.ai/threats/cve-2026-54234-vllm-denial-of-service-via-invalid-recovered-token-in-speculative"},{"cve":"CVE-2026-55646","cvss":6.5,"epss":0.0052,"slug":"cve-2026-55646-vllm-resource-exhaustion-in-speech-to-text-audio-upload-routes","title":"vLLM resource exhaustion in speech-to-text audio upload routes","severity":"medium","exploited":false,"published_at":"2026-07-06T20:16:37.663+00:00","url":"https://junglewise.ai/threats/cve-2026-55646-vllm-resource-exhaustion-in-speech-to-text-audio-upload-routes"},{"cve":"CVE-2024-11041","cvss":3,"epss":0.0156,"slug":"cve-2024-11041-vllm-deserialization-of-untrusted-data-vulnerability","title":"PYSEC-2026-566 - vLLM Deserialization of Untrusted Data vulnerability","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:35.17717+00:00","url":"https://junglewise.ai/threats/cve-2024-11041-vllm-deserialization-of-untrusted-data-vulnerability"},{"cve":"CVE-2024-9052","cvss":3,"slug":"cve-2024-9052-vllm-deserialization-vulnerability-in-vllm-distributed","title":"PYSEC-2026-568 - vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:34.951406+00:00","url":"https://junglewise.ai/threats/cve-2024-9052-vllm-deserialization-vulnerability-in-vllm-distributed"},{"cve":"CVE-2026-54236","cvss":5.3,"epss":0.0093,"slug":"cve-2026-54236-vllm-information-disclosure-via-unsanitized-error-messages-in","title":"vLLM information disclosure via unsanitized error messages in Anthropic and STT endpoints","severity":"medium","exploited":false,"published_at":"2026-06-22T23:16:31.29+00:00","url":"https://junglewise.ai/threats/cve-2026-54236-vllm-information-disclosure-via-unsanitized-error-messages-in"},{"cve":"CVE-2026-54235","cvss":4,"epss":0.0045,"slug":"cve-2026-54235-vllm-improper-input-validation-of-non-finite-floats-in-sampling","title":"vLLM improper input validation of non-finite floats in sampling parameters","severity":"medium","exploited":false,"published_at":"2026-06-22T23:16:31.143+00:00","url":"https://junglewise.ai/threats/cve-2026-54235-vllm-improper-input-validation-of-non-finite-floats-in-sampling"},{"cve":"CVE-2026-54233","cvss":6.5,"epss":0.0042,"slug":"cve-2026-54233-vllm-denial-of-service-via-audio-decompression-bomb-in","title":"vLLM denial of service via audio decompression bomb in transcriptions endpoint","severity":"medium","exploited":false,"published_at":"2026-06-22T23:16:31.007+00:00","url":"https://junglewise.ai/threats/cve-2026-54233-vllm-denial-of-service-via-audio-decompression-bomb-in"},{"cve":"CVE-2026-54232","cvss":8.8,"epss":0.0056,"slug":"cve-2026-54232-vllm-dependency-confusion-in-dockerfile-via-flashinfer-jit-cache","title":"vLLM dependency confusion in Dockerfile via flashinfer-jit-cache","severity":"high","exploited":false,"published_at":"2026-06-22T23:16:30.873+00:00","url":"https://junglewise.ai/threats/cve-2026-54232-vllm-dependency-confusion-in-dockerfile-via-flashinfer-jit-cache"},{"cve":"CVE-2026-53923","cvss":4,"epss":0.0048,"slug":"cve-2026-53923-vllm-information-disclosure-via-integer-truncation-in-gguf","title":"vLLM information disclosure via integer truncation in GGUF kernels","severity":"medium","exploited":false,"published_at":"2026-06-22T23:16:30.737+00:00","url":"https://junglewise.ai/threats/cve-2026-53923-vllm-information-disclosure-via-integer-truncation-in-gguf"},{"cve":"CVE-2026-48746","cvss":9.1,"epss":0.0115,"slug":"cve-2026-48746-vllm-authentication-bypass-in-openai-api-via-host-header","title":"vLLM authentication bypass in OpenAI API via Host header injection","severity":"critical","exploited":false,"published_at":"2026-06-22T23:16:30.49+00:00","url":"https://junglewise.ai/threats/cve-2026-48746-vllm-authentication-bypass-in-openai-api-via-host-header"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"vllm (PyPI)","slug":"pypi-vllm","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/pypi-vllm"},"most_severe":[{"cve":"CVE-2026-22778","cvss":9.8,"epss":0.0381,"slug":"cve-2026-22778-vllm-remote-code-execution-via-jpeg2000-heap-overflow-and-aslr","title":"vLLM remote code execution via JPEG2000 heap overflow and ASLR bypass","severity":"critical","exploited":false,"published_at":"2026-02-02T23:16:06.7+00:00","url":"https://junglewise.ai/threats/cve-2026-22778-vllm-remote-code-execution-via-jpeg2000-heap-overflow-and-aslr"},{"cve":"CVE-2024-9053","cvss":9.8,"epss":0.0138,"slug":"cve-2024-9053-vllm-remote-code-execution-via-pickle-deserialization-in","title":"vLLM remote code execution via pickle deserialization in AsyncEngineRPCServer","severity":"critical","exploited":false,"published_at":"2025-03-20T12:32:50+00:00","url":"https://junglewise.ai/threats/cve-2024-9053-vllm-remote-code-execution-via-pickle-deserialization-in"},{"cve":"CVE-2025-47277","cvss":9.8,"epss":0.0096,"slug":"cve-2025-47277-vllm-remote-code-execution-via-unsafe-deserialization-in","title":"vLLM remote code execution via unsafe deserialization in PyNcclPipe","severity":"critical","exploited":false,"published_at":"2025-05-20T18:04:30+00:00","url":"https://junglewise.ai/threats/cve-2025-47277-vllm-remote-code-execution-via-unsafe-deserialization-in"},{"cve":"CVE-2026-48746","cvss":9.1,"epss":0.0115,"slug":"cve-2026-48746-vllm-authentication-bypass-in-openai-api-via-host-header","title":"vLLM authentication bypass in OpenAI API via Host header injection","severity":"critical","exploited":false,"published_at":"2026-06-22T23:16:30.49+00:00","url":"https://junglewise.ai/threats/cve-2026-48746-vllm-authentication-bypass-in-openai-api-via-host-header"},{"cve":"CVE-2026-27893","cvss":8.8,"epss":0.0181,"slug":"cve-2026-27893-vllm-remote-code-execution-via-hardcoded-remote-code-trust-in","title":"vLLM remote code execution via hardcoded remote code trust in models","severity":"high","exploited":false,"published_at":"2026-03-27T00:16:22.333+00:00","url":"https://junglewise.ai/threats/cve-2026-27893-vllm-remote-code-execution-via-hardcoded-remote-code-trust-in"},{"cve":"CVE-2025-62164","cvss":8.8,"epss":0.0093,"slug":"cve-2025-62164-vllm-unsafe-deserialization-in-completions-api-prompt-embeddings","title":"vLLM unsafe deserialization in Completions API prompt embeddings","severity":"high","exploited":false,"published_at":"2025-11-20T20:59:34+00:00","url":"https://junglewise.ai/threats/cve-2025-62164-vllm-unsafe-deserialization-in-completions-api-prompt-embeddings"},{"cve":"CVE-2026-22807","cvss":8.8,"epss":0.0083,"slug":"cve-2026-22807-vllm-arbitrary-code-execution-via-auto-map-dynamic-module-loading","title":"vLLM arbitrary code execution via auto_map dynamic module loading","severity":"high","exploited":false,"published_at":"2026-01-21T22:15:49.077+00:00","url":"https://junglewise.ai/threats/cve-2026-22807-vllm-arbitrary-code-execution-via-auto-map-dynamic-module-loading"},{"cve":"CVE-2026-56340","cvss":8.8,"epss":0.0064,"slug":"cve-2026-56340-vllm-improper-input-validation-in-multimodal-embeddings","title":"vLLM improper input validation in multimodal embeddings","severity":"high","exploited":false,"published_at":"2026-06-20T19:16:23.567+00:00","url":"https://junglewise.ai/threats/cve-2026-56340-vllm-improper-input-validation-in-multimodal-embeddings"},{"cve":"CVE-2026-54232","cvss":8.8,"epss":0.0056,"slug":"cve-2026-54232-vllm-dependency-confusion-in-dockerfile-via-flashinfer-jit-cache","title":"vLLM dependency confusion in Dockerfile via flashinfer-jit-cache","severity":"high","exploited":false,"published_at":"2026-06-22T23:16:30.873+00:00","url":"https://junglewise.ai/threats/cve-2026-54232-vllm-dependency-confusion-in-dockerfile-via-flashinfer-jit-cache"},{"cve":"CVE-2025-30165","cvss":8,"epss":0.0048,"slug":"cve-2025-30165-vllm-rce-via-unsafe-pickle-deserialization-in-v0-engine","title":"vLLM RCE via unsafe pickle deserialization in V0 engine","severity":"high","exploited":false,"published_at":"2025-05-06T16:38:35+00:00","url":"https://junglewise.ai/threats/cve-2025-30165-vllm-rce-via-unsafe-pickle-deserialization-in-v0-engine"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}