Technology · Vllm
Vllm vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 21 vulnerabilities in Vllm: 0 in the last 7 days and 7 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-93592, was published on 18 September 2026.
- Last 7 days
- 0
- Last 90 days
- 7
- Critical, all time
- 1
- Exploited in the wild
- 0
About Vllm
A fast and easy-to-use library for LLM inference and serving.
Latest Vllm vulnerabilities
- CVE-2026-93592: vLLM input validation bypass in embeddings and pooling endpointshighCVSS 7.5EPSS 0.5%
- CVE-2026-93436: vLLM memory exhaustion in decode-side metadata cleanuphighCVSS 7.5EPSS 0.8%
- CVE-2026-90555: vLLM audio transcription endpoint denial of service via forged FLAC headersmediumCVSS 6.5EPSS 0.5%
- CVE-2026-90554: vLLM NanoNemotronVL audio extraction denial of servicemediumCVSS 6.2EPSS 0.2%
- CVE-2026-90553: vLLM LlavaOnevision2 processor remote code execution via trust_remote_code bypasshighCVSS 7.8EPSS 0.3%
- CVE-2026-78684: vLLM DeepStream backend classification and pixel-limit enforcement bypassmediumCVSS 5.3EPSS 0.6%
- CVE-2025-6242: PYSEC-2026-2011 - vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` classlowCVSS 3.1EPSS 0.3%
- vLLM missing tensor validation in multimodal embeddingshighCVSS 8.8
- CVE-2025-71379: vLLM ReDoS in multiple components including LoRA and OpenAI chat endpointmediumCVSS 4.3EPSS 0.5%
- vLLM improper image metadata normalization in image processingmediumCVSS 4.8
- vLLM interpretation conflict in image EXIF and transparency handlingmediumCVSS 4.8
- CVE-2026-4944: vLLM remote code execution via hardcoded trust_remote_code parameterhighCVSS 8.8
- CVE-2026-44223: vLLM denial of service in extract_hidden_states speculative decodingmediumCVSS 6.5EPSS 0.4%
- CVE-2026-34756: vLLM Denial of Service via unbounded n parameter in OpenAI API servermediumCVSS 6.5EPSS 0.8%
- CVE-2026-34755: vLLM denial of service via unbounded video frame processingmediumCVSS 6.5EPSS 0.8%
- CVE-2026-34760: vLLM-project vLLM improper input validation in audio downmixingmediumCVSS 5.9EPSS 0.5%
- CVE-2026-27893: vLLM remote code execution via hardcoded remote code trust in modelshighCVSS 8.8EPSS 1.8%
- CVE-2026-25960: vLLM SSRF protection bypass in MediaConnector via URL parsing inconsistencyhighCVSS 7.1EPSS 0.7%
- CVE-2026-22778: vLLM remote code execution via JPEG2000 heap overflow and ASLR bypasscriticalCVSS 9.8EPSS 3.8%
- CVE-2026-24779: vLLM SSRF in MediaConnector via URL parsing discrepancyhighCVSS 7.1EPSS 0.6%
- CVE-2026-22807: vLLM arbitrary code execution via auto_map dynamic module loadinghighCVSS 8.8EPSS 0.8%
Most severe Vllm vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-22778: vLLM remote code execution via JPEG2000 heap overflow and ASLR bypasscriticalCVSS 9.8EPSS 3.8%
- CVE-2026-27893: vLLM remote code execution via hardcoded remote code trust in modelshighCVSS 8.8EPSS 1.8%
- CVE-2026-22807: vLLM arbitrary code execution via auto_map dynamic module loadinghighCVSS 8.8EPSS 0.8%
- vLLM missing tensor validation in multimodal embeddingshighCVSS 8.8
- CVE-2026-4944: vLLM remote code execution via hardcoded trust_remote_code parameterhighCVSS 8.8
- CVE-2026-90553: vLLM LlavaOnevision2 processor remote code execution via trust_remote_code bypasshighCVSS 7.8EPSS 0.3%
- CVE-2026-93436: vLLM memory exhaustion in decode-side metadata cleanuphighCVSS 7.5EPSS 0.8%
- CVE-2026-93592: vLLM input validation bypass in embeddings and pooling endpointshighCVSS 7.5EPSS 0.5%
- CVE-2026-25960: vLLM SSRF protection bypass in MediaConnector via URL parsing inconsistencyhighCVSS 7.1EPSS 0.7%
- CVE-2026-24779: vLLM SSRF in MediaConnector via URL parsing discrepancyhighCVSS 7.1EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 3 | 0 | |
| 14 Sep 2026 | 2 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/vllm.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Vllm vulnerabilities", https://junglewise.ai/threats/technologies/vllm, 26 September 2026.