Skip to content
Threat Feed

Tag

VLLM

6 briefs RSS
high advisory

Remote Code Execution in vLLM LlavaOnevision2 Processor Loader

A vulnerability in vLLM versions prior to 0.28.0 allows remote code execution by bypassing the trust_remote_code parameter during the loading of malicious LlavaOnevision2 processor classes.

vLLM +2 remote-code-execution model-inference supply-chain denial-of-service vulnerability
1r 2t 1c updated
medium advisory

Denial of Service Vulnerability in vLLM

An authenticated remote attacker can exploit a vulnerability in vLLM to trigger a Denial of Service condition, likely through resource exhaustion.

vLLM denial-of-service cve-2024-53676 availability
1t 1c updated
low advisory

vLLM Denial of Service Vulnerability via M-RoPE Prompt Embeds (CVE-2026-55514)

A denial of service vulnerability, CVE-2026-55514, exists in vLLM versions from 0.12.0 up to, but not including, 0.24.0, allowing an authorized remote user to send a specially crafted `/v1/completions` request that leverages pure prompt embeds with an M-RoPE-enabled model to trigger an assertion failure, causing the vLLM server application to fatally crash.

vLLM denial-of-service large-language-model cve
1t 1c
critical advisory

vllm Vulnerability Allows Remote Code Execution

A remote, anonymous attacker can exploit a vulnerability in vllm to achieve arbitrary code execution.

vllm remote-code-execution vulnerability
2r 1t
high advisory

vllm and PyTorch Vulnerability Allows DoS and Potential Remote Code Execution

A remote, authenticated attacker can exploit a vulnerability in vllm and PyTorch to cause a denial-of-service condition or potentially achieve remote code execution.

vllm denial-of-service remote-code-execution PyTorch
2r 2t
critical advisory

vLLM Remote Code Execution Vulnerability (CVE-2026-27893)

vLLM versions before 0.18.0 are vulnerable to remote code execution due to hardcoded trust of remote code, even when explicitly disabled by the user, allowing attackers to execute arbitrary code via malicious model repositories.

vLLM RCE CVE-2026-27893
2r 1t