{"schema_version":1,"title":"vLLM Project vLLM vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 71 vulnerabilities in vLLM Project vLLM: 13 in the last 7 days and 33 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100654, was published on 26 September 2026.","url":"https://junglewise.ai/threats/technologies/vllm-project-vllm","json_url":"https://junglewise.ai/threats/technologies/vllm-project-vllm.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/vllm-project-vllm","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":24,"all_time":71,"critical":4,"exploited":0,"last_7_days":13,"last_30_days":27,"last_90_days":33,"last_365_days":63},"latest":[{"cve":"CVE-2026-100654","cvss":6.5,"slug":"cve-2026-100654-vllm-before-0-29-0-accepts-user-controlled-stop-token-ids-on-the","title":"vLLM improper array index validation in stop_token_ids","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:48.1+00:00","url":"https://junglewise.ai/threats/cve-2026-100654-vllm-before-0-29-0-accepts-user-controlled-stop-token-ids-on-the"},{"cve":"CVE-2026-100653","cvss":6.5,"slug":"cve-2026-100653-vllm-is-an-inference-and-serving-engine-for-large-language","title":"vLLM incomplete artifact pin propagation in FunAudioChat and Tarsier2","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:47.953+00:00","url":"https://junglewise.ai/threats/cve-2026-100653-vllm-is-an-inference-and-serving-engine-for-large-language"},{"cve":"CVE-2026-100652","cvss":5.9,"slug":"cve-2026-100652-vllm-versions-0-22-0-through-0-23-0-fail-to-validate-stop-token","title":"vLLM input validation bypass in stop_token_ids handling","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:47.81+00:00","url":"https://junglewise.ai/threats/cve-2026-100652-vllm-versions-0-22-0-through-0-23-0-fail-to-validate-stop-token"},{"cve":"CVE-2026-100651","cvss":6.5,"slug":"cve-2026-100651-vllm-before-0-29-0-fails-to-enforce-decoder-prompt-length","title":"vLLM decoder prompt-length validation bypass in disaggregated serving","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:47.663+00:00","url":"https://junglewise.ai/threats/cve-2026-100651-vllm-before-0-29-0-fails-to-enforce-decoder-prompt-length"},{"cve":"CVE-2026-100650","cvss":6.5,"slug":"cve-2026-100650-vllm-through-0-29-0-fetches-and-fully-materializes-remote-or","title":"vLLM resource exhaustion in media fetching before limit enforcement","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:47.523+00:00","url":"https://junglewise.ai/threats/cve-2026-100650-vllm-through-0-29-0-fetches-and-fully-materializes-remote-or"},{"cve":"CVE-2026-100648","cvss":5.3,"slug":"cve-2026-100648-vllm-before-0-29-0-fails-to-enforce-vllm-max-audio-clip-filesize","title":"vllm audio decoding resource consumption via unvalidated file size","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:47.24+00:00","url":"https://junglewise.ai/threats/cve-2026-100648-vllm-before-0-29-0-fails-to-enforce-vllm-max-audio-clip-filesize"},{"cve":"CVE-2026-100647","cvss":5.3,"slug":"cve-2026-100647-vllm-versions-before-0-29-0-contain-a-denial-of-service","title":"vLLM denial of service via unbounded cache_salt parameter","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:47.097+00:00","url":"https://junglewise.ai/threats/cve-2026-100647-vllm-versions-before-0-29-0-contain-a-denial-of-service"},{"cve":"CVE-2026-94627","cvss":7.5,"epss":0.0063,"slug":"cve-2026-94627-vllm-mooncake-connector-through-0-29-0-fails-to-properly-manage","title":"vLLM Mooncake connector GPU KV cache memory leak","severity":"high","exploited":false,"published_at":"2026-09-21T22:17:01.74+00:00","url":"https://junglewise.ai/threats/cve-2026-94627-vllm-mooncake-connector-through-0-29-0-fails-to-properly-manage"},{"cve":"CVE-2026-94626","cvss":7.5,"epss":0.0063,"slug":"cve-2026-94626-vllm-through-0-29-0-fails-to-validate-the-tp-size-parameter-in-kv","title":"vLLM input validation bypass in kv_transfer_params","severity":"high","exploited":false,"published_at":"2026-09-21T22:17:01.587+00:00","url":"https://junglewise.ai/threats/cve-2026-94626-vllm-through-0-29-0-fails-to-validate-the-tp-size-parameter-in-kv"},{"cve":"CVE-2026-94625","cvss":5.3,"epss":0.0052,"slug":"cve-2026-94625-vllm-through-0-29-0-contains-a-resource-exhaustion-vulnerability","title":"vLLM resource exhaustion in MooncakeConnector","severity":"medium","exploited":false,"published_at":"2026-09-21T22:17:01.433+00:00","url":"https://junglewise.ai/threats/cve-2026-94625-vllm-through-0-29-0-contains-a-resource-exhaustion-vulnerability"},{"cve":"CVE-2026-94624","cvss":7.5,"epss":0.0063,"slug":"cve-2026-94624-vllm-through-0-29-0-contains-a-denial-of-service-vulnerability-in","title":"vLLM denial of service in P2P KV offloading","severity":"high","exploited":false,"published_at":"2026-09-21T22:17:01.28+00:00","url":"https://junglewise.ai/threats/cve-2026-94624-vllm-through-0-29-0-contains-a-denial-of-service-vulnerability-in"},{"cve":"CVE-2026-94623","cvss":7.5,"epss":0.0063,"slug":"cve-2026-94623-vllm-through-0-29-0-contains-a-denial-of-service-vulnerability-in","title":"vLLM denial of service in NIXL prefix caching","severity":"high","exploited":false,"published_at":"2026-09-21T22:17:01.123+00:00","url":"https://junglewise.ai/threats/cve-2026-94623-vllm-through-0-29-0-contains-a-denial-of-service-vulnerability-in"},{"cve":"CVE-2026-94622","cvss":7.5,"epss":0.0063,"slug":"cve-2026-94622-vllm-versions-through-0-29-0-contain-a-denial-of-service","title":"vLLM denial of service in NIXL connector metadata handling","severity":"high","exploited":false,"published_at":"2026-09-21T22:17:00.96+00:00","url":"https://junglewise.ai/threats/cve-2026-94622-vllm-versions-through-0-29-0-contain-a-denial-of-service"},{"cve":"CVE-2026-69147","cvss":6.5,"epss":0.0055,"slug":"cve-2026-69147-vllm-request-selected-pynvvideocodec-gpu-decode-bypasses-vram","title":"vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can se","severity":"medium","exploited":false,"published_at":"2026-09-16T18:17:11.77+00:00","url":"https://junglewise.ai/threats/cve-2026-69147-vllm-request-selected-pynvvideocodec-gpu-decode-bypasses-vram"},{"cve":"CVE-2026-57173","cvss":6.5,"epss":0.0069,"slug":"cve-2026-57173-vllm-unauthenticated-audio-decompression-bomb-dos","title":"vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions c","severity":"medium","exploited":false,"published_at":"2026-09-16T17:17:24.603+00:00","url":"https://junglewise.ai/threats/cve-2026-57173-vllm-unauthenticated-audio-decompression-bomb-dos"},{"cve":"CVE-2026-92365","cvss":4.3,"epss":0.0052,"slug":"cve-2026-92365-vllm-inefficient-algorithm-in-thinking-budget-state","title":"vLLM inefficient algorithm in thinking budget state","severity":"medium","exploited":false,"published_at":"2026-09-16T14:17:16.897+00:00","url":"https://junglewise.ai/threats/cve-2026-92365-vllm-inefficient-algorithm-in-thinking-budget-state"},{"cve":"CVE-2026-92220","cvss":5.3,"epss":0.007,"slug":"cve-2026-92220-vllm-moriio-resource-exhaustion-in-acknowledgement-handler","title":"vLLM MoRIIO resource exhaustion in acknowledgement handler","severity":"medium","exploited":false,"published_at":"2026-09-16T03:17:00.407+00:00","url":"https://junglewise.ai/threats/cve-2026-92220-vllm-moriio-resource-exhaustion-in-acknowledgement-handler"},{"cve":"CVE-2026-90878","cvss":4.3,"epss":0.0053,"slug":"cve-2026-90878-vllm-jinja-template-rendering-denial-of-service","title":"vLLM Jinja template rendering denial of service","severity":"medium","exploited":false,"published_at":"2026-09-15T05:16:59.42+00:00","url":"https://junglewise.ai/threats/cve-2026-90878-vllm-jinja-template-rendering-denial-of-service"},{"cve":"CVE-2026-90713","cvss":3.3,"epss":0.0016,"slug":"cve-2026-90713-vllm-tiktoken-vocab-file-handler-denial-of-service","title":"vLLM tiktoken vocab file handler denial of service","severity":"low","exploited":false,"published_at":"2026-09-14T13:19:29.677+00:00","url":"https://junglewise.ai/threats/cve-2026-90713-vllm-tiktoken-vocab-file-handler-denial-of-service"},{"cve":"CVE-2026-90555","cvss":6.5,"epss":0.0052,"slug":"cve-2026-90555-vllm-audio-transcription-endpoint-denial-of-service-via-forged","title":"vLLM audio transcription endpoint denial of service via forged FLAC headers","severity":"medium","exploited":false,"published_at":"2026-09-12T13:16:54.18+00:00","url":"https://junglewise.ai/threats/cve-2026-90555-vllm-audio-transcription-endpoint-denial-of-service-via-forged"},{"cve":"CVE-2026-90553","cvss":7.8,"epss":0.0031,"slug":"cve-2026-90553-vllm-llavaonevision2-processor-remote-code-execution-via-trust","title":"vLLM LlavaOnevision2 processor remote code execution via trust_remote_code bypass","severity":"high","exploited":false,"published_at":"2026-09-12T13:16:53.887+00:00","url":"https://junglewise.ai/threats/cve-2026-90553-vllm-llavaonevision2-processor-remote-code-execution-via-trust"},{"cve":"CVE-2026-73560","cvss":6.5,"epss":0.0044,"slug":"cve-2026-73560-vllm-ssrf-and-arbitrary-file-read-in","title":"vLLM SSRF and arbitrary file read in MiMoV2OmniMultiModalProcessor","severity":"medium","exploited":false,"published_at":"2026-09-08T20:42:00+00:00","url":"https://junglewise.ai/threats/cve-2026-73560-vllm-ssrf-and-arbitrary-file-read-in"},{"cve":"CVE-2026-73558","cvss":5.3,"epss":0.004,"slug":"cve-2026-73558-vllm-integer-overflow-in-kernel-causing-cross-user-data-leak","title":"vLLM integer overflow in kernel causing cross-user data leak","severity":"medium","exploited":false,"published_at":"2026-09-08T20:24:49+00:00","url":"https://junglewise.ai/threats/cve-2026-73558-vllm-integer-overflow-in-kernel-causing-cross-user-data-leak"},{"cve":"CVE-2026-73557","cvss":4,"epss":0.004,"slug":"cve-2026-73557-vllm-concurrent-prompt-embedding-guard-bypass","title":"vLLM concurrent prompt-embedding guard bypass","severity":"medium","exploited":false,"published_at":"2026-09-04T21:39:02+00:00","url":"https://junglewise.ai/threats/cve-2026-73557-vllm-concurrent-prompt-embedding-guard-bypass"},{"cve":"CVE-2026-73556","cvss":5.3,"epss":0.0052,"slug":"cve-2026-73556-vllm-redos-in-lm-format-enforcer-backend-regex-parsing","title":"vLLM ReDoS in lm-format-enforcer backend regex parsing","severity":"medium","exploited":false,"published_at":"2026-09-04T21:37:00+00:00","url":"https://junglewise.ai/threats/cve-2026-73556-vllm-redos-in-lm-format-enforcer-backend-regex-parsing"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":13}],"related":[],"technology":{"hub":true,"name":"vLLM Project vLLM","slug":"vllm-project-vllm","vendor":{"name":"vLLM Project","slug":"vllm-project","url":"https://junglewise.ai/threats/vendors/vllm-project"},"aliases":[],"category":"library","homepage":"https://vllm.ai/","repo_url":"https://github.com/vllm-project/vllm","description":"vLLM is an open-source library for high-throughput serving of large language models.","url":"https://junglewise.ai/threats/technologies/vllm-project-vllm"},"most_severe":[{"cve":"CVE-2026-22778","cvss":9.8,"epss":0.0381,"slug":"cve-2026-22778-vllm-remote-code-execution-via-jpeg2000-heap-overflow-and-aslr","title":"vLLM remote code execution via JPEG2000 heap overflow and ASLR bypass","severity":"critical","exploited":false,"published_at":"2026-02-02T23:16:06.7+00:00","url":"https://junglewise.ai/threats/cve-2026-22778-vllm-remote-code-execution-via-jpeg2000-heap-overflow-and-aslr"},{"cve":"CVE-2024-9053","cvss":9.8,"epss":0.0138,"slug":"cve-2024-9053-vllm-remote-code-execution-via-pickle-deserialization-in","title":"vLLM remote code execution via pickle deserialization in AsyncEngineRPCServer","severity":"critical","exploited":false,"published_at":"2025-03-20T12:32:50+00:00","url":"https://junglewise.ai/threats/cve-2024-9053-vllm-remote-code-execution-via-pickle-deserialization-in"},{"cve":"CVE-2025-47277","cvss":9.8,"epss":0.0096,"slug":"cve-2025-47277-vllm-remote-code-execution-via-unsafe-deserialization-in","title":"vLLM remote code execution via unsafe deserialization in PyNcclPipe","severity":"critical","exploited":false,"published_at":"2025-05-20T18:04:30+00:00","url":"https://junglewise.ai/threats/cve-2025-47277-vllm-remote-code-execution-via-unsafe-deserialization-in"},{"cve":"CVE-2026-48746","cvss":9.1,"epss":0.0115,"slug":"cve-2026-48746-vllm-authentication-bypass-in-openai-api-via-host-header","title":"vLLM authentication bypass in OpenAI API via Host header injection","severity":"critical","exploited":false,"published_at":"2026-06-22T23:16:30.49+00:00","url":"https://junglewise.ai/threats/cve-2026-48746-vllm-authentication-bypass-in-openai-api-via-host-header"},{"cve":"CVE-2026-27893","cvss":8.8,"epss":0.0181,"slug":"cve-2026-27893-vllm-remote-code-execution-via-hardcoded-remote-code-trust-in","title":"vLLM remote code execution via hardcoded remote code trust in models","severity":"high","exploited":false,"published_at":"2026-03-27T00:16:22.333+00:00","url":"https://junglewise.ai/threats/cve-2026-27893-vllm-remote-code-execution-via-hardcoded-remote-code-trust-in"},{"cve":"CVE-2025-62164","cvss":8.8,"epss":0.0093,"slug":"cve-2025-62164-vllm-unsafe-deserialization-in-completions-api-prompt-embeddings","title":"vLLM unsafe deserialization in Completions API prompt embeddings","severity":"high","exploited":false,"published_at":"2025-11-20T20:59:34+00:00","url":"https://junglewise.ai/threats/cve-2025-62164-vllm-unsafe-deserialization-in-completions-api-prompt-embeddings"},{"cve":"CVE-2026-22807","cvss":8.8,"epss":0.0083,"slug":"cve-2026-22807-vllm-arbitrary-code-execution-via-auto-map-dynamic-module-loading","title":"vLLM arbitrary code execution via auto_map dynamic module loading","severity":"high","exploited":false,"published_at":"2026-01-21T22:15:49.077+00:00","url":"https://junglewise.ai/threats/cve-2026-22807-vllm-arbitrary-code-execution-via-auto-map-dynamic-module-loading"},{"cve":"CVE-2026-56340","cvss":8.8,"epss":0.0064,"slug":"cve-2026-56340-vllm-improper-input-validation-in-multimodal-embeddings","title":"vLLM improper input validation in multimodal embeddings","severity":"high","exploited":false,"published_at":"2026-06-20T19:16:23.567+00:00","url":"https://junglewise.ai/threats/cve-2026-56340-vllm-improper-input-validation-in-multimodal-embeddings"},{"cve":"CVE-2026-54232","cvss":8.8,"epss":0.0056,"slug":"cve-2026-54232-vllm-dependency-confusion-in-dockerfile-via-flashinfer-jit-cache","title":"vLLM dependency confusion in Dockerfile via flashinfer-jit-cache","severity":"high","exploited":false,"published_at":"2026-06-22T23:16:30.873+00:00","url":"https://junglewise.ai/threats/cve-2026-54232-vllm-dependency-confusion-in-dockerfile-via-flashinfer-jit-cache"},{"cve":"CVE-2025-30165","cvss":8,"epss":0.0048,"slug":"cve-2025-30165-vllm-rce-via-unsafe-pickle-deserialization-in-v0-engine","title":"vLLM RCE via unsafe pickle deserialization in V0 engine","severity":"high","exploited":false,"published_at":"2025-05-06T16:38:35+00:00","url":"https://junglewise.ai/threats/cve-2025-30165-vllm-rce-via-unsafe-pickle-deserialization-in-v0-engine"}],"generated_at":"2026-09-26T15:07:00.181821+00:00"}