{"schema_version":1,"title":"vLLM Project vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 68 vulnerabilities in vLLM Project: 6 in the last 7 days and 26 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-94627, was published on 21 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/vllm-project","json_url":"https://junglewise.ai/threats/vendors/vllm-project.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/vllm-project","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":25,"all_time":68,"critical":4,"exploited":0,"last_7_days":6,"last_30_days":20,"last_90_days":26,"last_365_days":60},"latest":[{"cve":"CVE-2026-94627","cvss":7.5,"epss":0.0063,"slug":"cve-2026-94627-vllm-mooncake-connector-through-0-29-0-fails-to-properly-manage","title":"vLLM Mooncake connector GPU KV cache memory leak","severity":"high","exploited":false,"published_at":"2026-09-21T22:17:01.74+00:00","url":"https://junglewise.ai/threats/cve-2026-94627-vllm-mooncake-connector-through-0-29-0-fails-to-properly-manage"},{"cve":"CVE-2026-94626","cvss":7.5,"epss":0.0063,"slug":"cve-2026-94626-vllm-through-0-29-0-fails-to-validate-the-tp-size-parameter-in-kv","title":"vLLM input validation bypass in kv_transfer_params","severity":"high","exploited":false,"published_at":"2026-09-21T22:17:01.587+00:00","url":"https://junglewise.ai/threats/cve-2026-94626-vllm-through-0-29-0-fails-to-validate-the-tp-size-parameter-in-kv"},{"cve":"CVE-2026-94625","cvss":5.3,"epss":0.0052,"slug":"cve-2026-94625-vllm-through-0-29-0-contains-a-resource-exhaustion-vulnerability","title":"vLLM resource exhaustion in MooncakeConnector","severity":"medium","exploited":false,"published_at":"2026-09-21T22:17:01.433+00:00","url":"https://junglewise.ai/threats/cve-2026-94625-vllm-through-0-29-0-contains-a-resource-exhaustion-vulnerability"},{"cve":"CVE-2026-94624","cvss":7.5,"epss":0.0063,"slug":"cve-2026-94624-vllm-through-0-29-0-contains-a-denial-of-service-vulnerability-in","title":"vLLM denial of service in P2P KV offloading","severity":"high","exploited":false,"published_at":"2026-09-21T22:17:01.28+00:00","url":"https://junglewise.ai/threats/cve-2026-94624-vllm-through-0-29-0-contains-a-denial-of-service-vulnerability-in"},{"cve":"CVE-2026-94623","cvss":7.5,"epss":0.0063,"slug":"cve-2026-94623-vllm-through-0-29-0-contains-a-denial-of-service-vulnerability-in","title":"vLLM denial of service in NIXL prefix caching","severity":"high","exploited":false,"published_at":"2026-09-21T22:17:01.123+00:00","url":"https://junglewise.ai/threats/cve-2026-94623-vllm-through-0-29-0-contains-a-denial-of-service-vulnerability-in"},{"cve":"CVE-2026-94622","cvss":7.5,"epss":0.0063,"slug":"cve-2026-94622-vllm-versions-through-0-29-0-contain-a-denial-of-service","title":"vLLM denial of service in NIXL connector metadata handling","severity":"high","exploited":false,"published_at":"2026-09-21T22:17:00.96+00:00","url":"https://junglewise.ai/threats/cve-2026-94622-vllm-versions-through-0-29-0-contain-a-denial-of-service"},{"cve":"CVE-2026-69147","cvss":6.5,"epss":0.0055,"slug":"cve-2026-69147-vllm-request-selected-pynvvideocodec-gpu-decode-bypasses-vram","title":"vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can se","severity":"medium","exploited":false,"published_at":"2026-09-16T18:17:11.77+00:00","url":"https://junglewise.ai/threats/cve-2026-69147-vllm-request-selected-pynvvideocodec-gpu-decode-bypasses-vram"},{"cve":"CVE-2026-57173","cvss":6.5,"epss":0.0069,"slug":"cve-2026-57173-vllm-unauthenticated-audio-decompression-bomb-dos","title":"vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions c","severity":"medium","exploited":false,"published_at":"2026-09-16T17:17:24.603+00:00","url":"https://junglewise.ai/threats/cve-2026-57173-vllm-unauthenticated-audio-decompression-bomb-dos"},{"cve":"CVE-2026-92365","cvss":4.3,"epss":0.0052,"slug":"cve-2026-92365-vllm-inefficient-algorithm-in-thinking-budget-state","title":"vLLM inefficient algorithm in thinking budget state","severity":"medium","exploited":false,"published_at":"2026-09-16T14:17:16.897+00:00","url":"https://junglewise.ai/threats/cve-2026-92365-vllm-inefficient-algorithm-in-thinking-budget-state"},{"cve":"CVE-2026-92220","cvss":5.3,"epss":0.007,"slug":"cve-2026-92220-vllm-moriio-resource-exhaustion-in-acknowledgement-handler","title":"vLLM MoRIIO resource exhaustion in acknowledgement handler","severity":"medium","exploited":false,"published_at":"2026-09-16T03:17:00.407+00:00","url":"https://junglewise.ai/threats/cve-2026-92220-vllm-moriio-resource-exhaustion-in-acknowledgement-handler"},{"cve":"CVE-2026-90878","cvss":4.3,"epss":0.0053,"slug":"cve-2026-90878-vllm-jinja-template-rendering-denial-of-service","title":"vLLM Jinja template rendering denial of service","severity":"medium","exploited":false,"published_at":"2026-09-15T05:16:59.42+00:00","url":"https://junglewise.ai/threats/cve-2026-90878-vllm-jinja-template-rendering-denial-of-service"},{"cve":"CVE-2026-90713","cvss":3.3,"epss":0.0016,"slug":"cve-2026-90713-vllm-tiktoken-vocab-file-handler-denial-of-service","title":"vLLM tiktoken vocab file handler denial of service","severity":"low","exploited":false,"published_at":"2026-09-14T13:19:29.677+00:00","url":"https://junglewise.ai/threats/cve-2026-90713-vllm-tiktoken-vocab-file-handler-denial-of-service"},{"cve":"CVE-2026-90555","cvss":6.5,"epss":0.0052,"slug":"cve-2026-90555-vllm-audio-transcription-endpoint-denial-of-service-via-forged","title":"vLLM audio transcription endpoint denial of service via forged FLAC headers","severity":"medium","exploited":false,"published_at":"2026-09-12T13:16:54.18+00:00","url":"https://junglewise.ai/threats/cve-2026-90555-vllm-audio-transcription-endpoint-denial-of-service-via-forged"},{"cve":"CVE-2026-90553","cvss":7.8,"epss":0.0031,"slug":"cve-2026-90553-vllm-llavaonevision2-processor-remote-code-execution-via-trust","title":"vLLM LlavaOnevision2 processor remote code execution via trust_remote_code bypass","severity":"high","exploited":false,"published_at":"2026-09-12T13:16:53.887+00:00","url":"https://junglewise.ai/threats/cve-2026-90553-vllm-llavaonevision2-processor-remote-code-execution-via-trust"},{"cve":"CVE-2026-73560","cvss":6.5,"epss":0.0044,"slug":"cve-2026-73560-vllm-ssrf-and-arbitrary-file-read-in","title":"vLLM SSRF and arbitrary file read in MiMoV2OmniMultiModalProcessor","severity":"medium","exploited":false,"published_at":"2026-09-08T20:42:00+00:00","url":"https://junglewise.ai/threats/cve-2026-73560-vllm-ssrf-and-arbitrary-file-read-in"},{"cve":"CVE-2026-73558","cvss":5.3,"epss":0.004,"slug":"cve-2026-73558-vllm-integer-overflow-in-kernel-causing-cross-user-data-leak","title":"vLLM integer overflow in kernel causing cross-user data leak","severity":"medium","exploited":false,"published_at":"2026-09-08T20:24:49+00:00","url":"https://junglewise.ai/threats/cve-2026-73558-vllm-integer-overflow-in-kernel-causing-cross-user-data-leak"},{"cve":"CVE-2026-73557","cvss":4,"epss":0.004,"slug":"cve-2026-73557-vllm-concurrent-prompt-embedding-guard-bypass","title":"vLLM concurrent prompt-embedding guard bypass","severity":"medium","exploited":false,"published_at":"2026-09-04T21:39:02+00:00","url":"https://junglewise.ai/threats/cve-2026-73557-vllm-concurrent-prompt-embedding-guard-bypass"},{"cve":"CVE-2026-73556","cvss":5.3,"epss":0.0052,"slug":"cve-2026-73556-vllm-redos-in-lm-format-enforcer-backend-regex-parsing","title":"vLLM ReDoS in lm-format-enforcer backend regex parsing","severity":"medium","exploited":false,"published_at":"2026-09-04T21:37:00+00:00","url":"https://junglewise.ai/threats/cve-2026-73556-vllm-redos-in-lm-format-enforcer-backend-regex-parsing"},{"cve":"CVE-2026-73555","cvss":5.3,"epss":0.0042,"slug":"cve-2026-73555-vllm-information-disclosure-via-validation-error-messages","title":"vLLM information disclosure via validation error messages","severity":"medium","exploited":false,"published_at":"2026-09-04T21:36:33+00:00","url":"https://junglewise.ai/threats/cve-2026-73555-vllm-information-disclosure-via-validation-error-messages"},{"cve":"CVE-2026-37237","cvss":7.5,"epss":0.0075,"slug":"cve-2026-37237-vllm-memory-exhaustion-in-multimodal-media-fetching","title":"vLLM memory exhaustion in multimodal media fetching","severity":"high","exploited":false,"published_at":"2026-08-28T16:17:46.3+00:00","url":"https://junglewise.ai/threats/cve-2026-37237-vllm-memory-exhaustion-in-multimodal-media-fetching"},{"cve":"CVE-2026-71486","cvss":4.3,"epss":0.0047,"slug":"cve-2026-71486-vllm-derender-endpoints-unbounded-token-decoding-dos","title":"vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/de","severity":"medium","exploited":false,"published_at":"2026-08-17T20:16:45.927+00:00","url":"https://junglewise.ai/threats/cve-2026-71486-vllm-derender-endpoints-unbounded-token-decoding-dos"},{"cve":"CVE-2026-73559","cvss":6.5,"epss":0.0055,"slug":"cve-2026-73559-vllm-completion-prompt-lists-dos","title":"vLLM completion prompt lists DoS","severity":"medium","exploited":false,"published_at":"2026-08-13T18:40:06+00:00","url":"https://junglewise.ai/threats/cve-2026-73559-vllm-completion-prompt-lists-dos"},{"cve":"CVE-2026-55574","cvss":7.5,"epss":0.0058,"slug":"cve-2026-55574-vllm-redos-in-structured-outputs-regex-api-parameter","title":"vLLM ReDoS in structured_outputs.regex API parameter","severity":"high","exploited":false,"published_at":"2026-07-06T21:16:57.347+00:00","url":"https://junglewise.ai/threats/cve-2026-55574-vllm-redos-in-structured-outputs-regex-api-parameter"},{"cve":"CVE-2026-55514","cvss":4,"epss":0.0067,"slug":"cve-2026-55514-vllm-denial-of-service-via-reachable-assertion-in-m-rope-models","title":"vLLM denial of service via reachable assertion in M-RoPE models","severity":"high","exploited":false,"published_at":"2026-07-06T21:16:57.207+00:00","url":"https://junglewise.ai/threats/cve-2026-55514-vllm-denial-of-service-via-reachable-assertion-in-m-rope-models"},{"cve":"CVE-2026-54234","cvss":7.5,"epss":0.0062,"slug":"cve-2026-54234-vllm-denial-of-service-via-invalid-recovered-token-in-speculative","title":"vLLM denial of service via invalid recovered token in speculative decoding","severity":"high","exploited":false,"published_at":"2026-07-06T21:16:56.477+00:00","url":"https://junglewise.ai/threats/cve-2026-54234-vllm-denial-of-service-via-invalid-recovered-token-in-speculative"}],"vendor":{"hub":true,"name":"vLLM Project","slug":"vllm-project","homepage":"https://vllm.ai/","description":"An open-source project focused on developing a high-throughput and memory-efficient serving engine for large language models.","url":"https://junglewise.ai/threats/vendors/vllm-project"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":6}],"most_severe":[{"cve":"CVE-2026-22778","cvss":9.8,"epss":0.0381,"slug":"cve-2026-22778-vllm-remote-code-execution-via-jpeg2000-heap-overflow-and-aslr","title":"vLLM remote code execution via JPEG2000 heap overflow and ASLR bypass","severity":"critical","exploited":false,"published_at":"2026-02-02T23:16:06.7+00:00","url":"https://junglewise.ai/threats/cve-2026-22778-vllm-remote-code-execution-via-jpeg2000-heap-overflow-and-aslr"},{"cve":"CVE-2024-9053","cvss":9.8,"epss":0.0138,"slug":"cve-2024-9053-vllm-remote-code-execution-via-pickle-deserialization-in","title":"vLLM remote code execution via pickle deserialization in AsyncEngineRPCServer","severity":"critical","exploited":false,"published_at":"2025-03-20T12:32:50+00:00","url":"https://junglewise.ai/threats/cve-2024-9053-vllm-remote-code-execution-via-pickle-deserialization-in"},{"cve":"CVE-2025-47277","cvss":9.8,"epss":0.0096,"slug":"cve-2025-47277-vllm-remote-code-execution-via-unsafe-deserialization-in","title":"vLLM remote code execution via unsafe deserialization in PyNcclPipe","severity":"critical","exploited":false,"published_at":"2025-05-20T18:04:30+00:00","url":"https://junglewise.ai/threats/cve-2025-47277-vllm-remote-code-execution-via-unsafe-deserialization-in"},{"cve":"CVE-2026-48746","cvss":9.1,"epss":0.0115,"slug":"cve-2026-48746-vllm-authentication-bypass-in-openai-api-via-host-header","title":"vLLM authentication bypass in OpenAI API via Host header injection","severity":"critical","exploited":false,"published_at":"2026-06-22T23:16:30.49+00:00","url":"https://junglewise.ai/threats/cve-2026-48746-vllm-authentication-bypass-in-openai-api-via-host-header"},{"cve":"CVE-2026-27893","cvss":8.8,"epss":0.0181,"slug":"cve-2026-27893-vllm-remote-code-execution-via-hardcoded-remote-code-trust-in","title":"vLLM remote code execution via hardcoded remote code trust in models","severity":"high","exploited":false,"published_at":"2026-03-27T00:16:22.333+00:00","url":"https://junglewise.ai/threats/cve-2026-27893-vllm-remote-code-execution-via-hardcoded-remote-code-trust-in"},{"cve":"CVE-2025-62164","cvss":8.8,"epss":0.0093,"slug":"cve-2025-62164-vllm-unsafe-deserialization-in-completions-api-prompt-embeddings","title":"vLLM unsafe deserialization in Completions API prompt embeddings","severity":"high","exploited":false,"published_at":"2025-11-20T20:59:34+00:00","url":"https://junglewise.ai/threats/cve-2025-62164-vllm-unsafe-deserialization-in-completions-api-prompt-embeddings"},{"cve":"CVE-2026-22807","cvss":8.8,"epss":0.0083,"slug":"cve-2026-22807-vllm-arbitrary-code-execution-via-auto-map-dynamic-module-loading","title":"vLLM arbitrary code execution via auto_map dynamic module loading","severity":"high","exploited":false,"published_at":"2026-01-21T22:15:49.077+00:00","url":"https://junglewise.ai/threats/cve-2026-22807-vllm-arbitrary-code-execution-via-auto-map-dynamic-module-loading"},{"cve":"CVE-2026-56340","cvss":8.8,"epss":0.0064,"slug":"cve-2026-56340-vllm-improper-input-validation-in-multimodal-embeddings","title":"vLLM improper input validation in multimodal embeddings","severity":"high","exploited":false,"published_at":"2026-06-20T19:16:23.567+00:00","url":"https://junglewise.ai/threats/cve-2026-56340-vllm-improper-input-validation-in-multimodal-embeddings"},{"cve":"CVE-2026-54232","cvss":8.8,"epss":0.0056,"slug":"cve-2026-54232-vllm-dependency-confusion-in-dockerfile-via-flashinfer-jit-cache","title":"vLLM dependency confusion in Dockerfile via flashinfer-jit-cache","severity":"high","exploited":false,"published_at":"2026-06-22T23:16:30.873+00:00","url":"https://junglewise.ai/threats/cve-2026-54232-vllm-dependency-confusion-in-dockerfile-via-flashinfer-jit-cache"},{"cve":"CVE-2026-4944","cvss":8.8,"slug":"cve-2026-4944-vllm-remote-code-execution-via-hardcoded-trust-remote-code","title":"vLLM remote code execution via hardcoded trust_remote_code parameter","severity":"high","exploited":false,"published_at":"2026-05-28T19:16:42.677+00:00","url":"https://junglewise.ai/threats/cve-2026-4944-vllm-remote-code-execution-via-hardcoded-trust-remote-code"}],"generated_at":"2026-09-26T13:07:00.120236+00:00","technologies":[{"name":"vLLM Project vLLM","slug":"vllm-project-vllm","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/vllm-project-vllm"}]}