Junglewise Threat Intelligence

vLLM Regular Expression Denial of Service

Severity: medium · CVSS 4.3 · Published 2026-06-20

Technologies: vLLM Project vllm. Vendors: vLLM Project.

Executive brief

vLLM is an open-source large language model inference framework used to serve AI models at scale. Multiple inefficient regular expressions in vLLM's LoRA module, tool parsing, and chat endpoints can be exploited to consume excessive CPU resources when an authenticated user submits maliciously crafted input. An attacker can trigger a denial of service, making the inference service unavailable to legitimate requests.

Technical details

This is a ReDoS (Regular Expression Denial of Service) vulnerability class, specifically CWE-1333 (Inefficient Regular Expression Complexity). The vulnerable regex patterns include: (1) r"\((.*?)\)\$?

quot; in vllm/lora/utils.py line 173 for parsing module names; (2) r'functools\[(.*?)\]' in the phi4mini tool parser using re.DOTALL; (3) r'.*"parameters":\s*(.*)' in the OpenAI serving chat endpoint; and (4) r'\{.*\}' in benchmark utilities. All exhibit catastrophic backtracking when fed nested or repeated input structures. Attack vector is network-based, requiring low privileges (authenticated user). An attacker can trigger severe performance degradation, exhausting CPU cycles and causing denial of service. The vulnerability is patched in vLLM 0.9.0.

Affected products

  • vLLM Project vLLM >= 0.6.3, < 0.9.0

Timeline

  • 2025-05-28: disclosed: Original advisory GHSA-j828-28rj-hfhp published
  • 2026-06-20: advisory: Duplicate advisory GHSA-vfm7-4h43-gp6m published; CVE-2025-71379 assigned
  • 2026-09-11: other: Duplicate advisory withdrawn; primary advisory is GHSA-j828-28rj-hfhp

References