Vendor
vLLM Project vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 68 vulnerabilities in vLLM Project: 6 in the last 7 days and 26 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-94627, was published on 21 September 2026. 1 technology has a page of its own.
- Last 7 days
- 6
- Last 90 days
- 26
- Critical, all time
- 4
- Exploited in the wild
- 0
About vLLM Project
An open-source project focused on developing a high-throughput and memory-efficient serving engine for large language models.
vLLM Project technologies
Latest vLLM Project vulnerabilities
- CVE-2026-94627: vLLM Mooncake connector GPU KV cache memory leakhighCVSS 7.5EPSS 0.6%
- CVE-2026-94626: vLLM input validation bypass in kv_transfer_paramshighCVSS 7.5EPSS 0.6%
- CVE-2026-94625: vLLM resource exhaustion in MooncakeConnectormediumCVSS 5.3EPSS 0.5%
- CVE-2026-94624: vLLM denial of service in P2P KV offloadinghighCVSS 7.5EPSS 0.6%
- CVE-2026-94623: vLLM denial of service in NIXL prefix cachinghighCVSS 7.5EPSS 0.6%
- CVE-2026-94622: vLLM denial of service in NIXL connector metadata handlinghighCVSS 7.5EPSS 0.6%
- CVE-2026-69147: vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions…mediumCVSS 6.5EPSS 0.5%
- CVE-2026-57173: vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for…mediumCVSS 6.5EPSS 0.7%
- CVE-2026-92365: vLLM inefficient algorithm in thinking budget statemediumCVSS 4.3EPSS 0.5%
- CVE-2026-92220: vLLM MoRIIO resource exhaustion in acknowledgement handlermediumCVSS 5.3EPSS 0.7%
- CVE-2026-90878: vLLM Jinja template rendering denial of servicemediumCVSS 4.3EPSS 0.5%
- CVE-2026-90713: vLLM tiktoken vocab file handler denial of servicelowCVSS 3.3EPSS 0.2%
- CVE-2026-90555: vLLM audio transcription endpoint denial of service via forged FLAC headersmediumCVSS 6.5EPSS 0.5%
- CVE-2026-90553: vLLM LlavaOnevision2 processor remote code execution via trust_remote_code bypasshighCVSS 7.8EPSS 0.3%
- CVE-2026-73560: vLLM SSRF and arbitrary file read in MiMoV2OmniMultiModalProcessormediumCVSS 6.5EPSS 0.4%
- CVE-2026-73558: vLLM integer overflow in kernel causing cross-user data leakmediumCVSS 5.3EPSS 0.4%
- CVE-2026-73557: vLLM concurrent prompt-embedding guard bypassmediumCVSS 4EPSS 0.4%
- CVE-2026-73556: vLLM ReDoS in lm-format-enforcer backend regex parsingmediumCVSS 5.3EPSS 0.5%
- CVE-2026-73555: vLLM information disclosure via validation error messagesmediumCVSS 5.3EPSS 0.4%
- CVE-2026-37237: vLLM memory exhaustion in multimodal media fetchinghighCVSS 7.5EPSS 0.8%
- CVE-2026-71486: vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and…mediumCVSS 4.3EPSS 0.5%
- CVE-2026-73559: vLLM completion prompt lists DoSmediumCVSS 6.5EPSS 0.5%
- CVE-2026-55574: vLLM ReDoS in structured_outputs.regex API parameterhighCVSS 7.5EPSS 0.6%
- CVE-2026-55514: vLLM denial of service via reachable assertion in M-RoPE modelshighCVSS 4EPSS 0.7%
- CVE-2026-54234: vLLM denial of service via invalid recovered token in speculative decodinghighCVSS 7.5EPSS 0.6%
Most severe vLLM Project vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-22778: vLLM remote code execution via JPEG2000 heap overflow and ASLR bypasscriticalCVSS 9.8EPSS 3.8%
- CVE-2024-9053: vLLM remote code execution via pickle deserialization in AsyncEngineRPCServercriticalCVSS 9.8EPSS 1.4%
- CVE-2025-47277: vLLM remote code execution via unsafe deserialization in PyNcclPipecriticalCVSS 9.8EPSS 1.0%
- CVE-2026-48746: vLLM authentication bypass in OpenAI API via Host header injectioncriticalCVSS 9.1EPSS 1.1%
- CVE-2026-27893: vLLM remote code execution via hardcoded remote code trust in modelshighCVSS 8.8EPSS 1.8%
- CVE-2025-62164: vLLM unsafe deserialization in Completions API prompt embeddingshighCVSS 8.8EPSS 0.9%
- CVE-2026-22807: vLLM arbitrary code execution via auto_map dynamic module loadinghighCVSS 8.8EPSS 0.8%
- CVE-2026-56340: vLLM improper input validation in multimodal embeddingshighCVSS 8.8EPSS 0.6%
- CVE-2026-54232: vLLM dependency confusion in Dockerfile via flashinfer-jit-cachehighCVSS 8.8EPSS 0.6%
- CVE-2026-4944: vLLM remote code execution via hardcoded trust_remote_code parameterhighCVSS 8.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 4 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 1 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 3 | 0 | |
| 7 Sep 2026 | 4 | 0 | |
| 14 Sep 2026 | 6 | 0 | |
| 21 Sep 2026 | 6 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/vllm-project.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "vLLM Project vulnerabilities", https://junglewise.ai/threats/vendors/vllm-project, 26 September 2026.