vendor

vllm

24 thingsrelated by NVD

Its products

vllm 24

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

vllm: vLLM: Denial of Service via GPU memory exhaustion
CVE-2026-94627
Severity high
vllm: vLLM: Denial of Service via unvalidated memory allocation parameter
CVE-2026-94626
Severity high
vllm: vLLM: Resource exhaustion via rejected prefill requests
CVE-2026-94625
Severity high
vllm: vLLM: Denial of Service via unbounded P2P KV offloading sessions
CVE-2026-94624
Severity high
vllm: vLLM: Denial of Service via NIXL multi-prompt assertion failure
CVE-2026-94623
Severity high
vllm: vLLM: Denial of Service via Incomplete NIXL KV Transfer Metadata
CVE-2026-94622
Severity high
vllm: vLLM: Cross-request logits corruption via out-of-bounds token indices
CVE-2026-93989
Severity medium
vllm: vLLM: Memory corruption via unvalidated prompt token IDs
CVE-2026-93841
Severity medium
vllm: vLLM: Information disclosure via incorrect token ID validation
CVE-2026-93840
Severity medium
vllm: vLLM: Denial of Service via negative token ID input
CVE-2026-93592
Severity high
vllm: vLLM: Denial of Service via memory exhaustion from rejected requests
CVE-2026-93436
Severity high
vllm: vLLM: Denial of Service due to improper audio header validation
CVE-2026-90555
Severity medium
vllm: vLLM: Denial of Service via video audio extraction
CVE-2026-90554
Severity high
vllm: vLLM: Remote Code Execution via LlavaOnevision2 processor ignoring trust_remote_code
CVE-2026-90553
Severity high
vllm: vLLM: Denial of Service via DeepStream backend resource control bypass.
CVE-2026-78684
Severity medium
vllm: vLLM: Server-Side Request Forgery and arbitrary file read via improper media processing
CVE-2026-73560
Severity medium
vllm: vLLM: Denial of Service via unbounded completion prompt lists
CVE-2026-73559
Severity medium
vllm: vLLM: Cross-User Data Leakage via Integer Overflow
CVE-2026-73558
Severity medium
vllm: vLLM: Denial of Service via Regular Expression processing
CVE-2026-73556
Severity high
vllm: vLLM: Information Disclosure via Validation Error Messages
CVE-2026-73555
Severity medium
vllm: vLLM: Denial of Service via unbounded token ID decoding
CVE-2026-71486
Severity medium
vllm: starlette: vLLM: Critical authentication bypass allows unauthorized API access
CVE-2026-48746
Severity critical
vllm: vLLM: Denial of Service via memory exhaustion from oversized media files
CVE-2026-37237
Severity high
vllm: vLLM: Denial of Service via regular expression denial of service (ReDoS) vulnerabilities
CVE-2025-71379
Severity high