Vllm-project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 49
    Known Exploited: 0
    5
    Critical Level Threats
    15
    High Level Threats
    26
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-37237

    vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py fetch user-supplied media URLs using aiohttp and call r.read() without enforcing a maximum response size, allowing an attacker to exhaust server memory by providing a URL to an arbitrarily large file.

    Last Modified: Aug 28, 2026
    Published: Aug 28, 2026

    CVE-2026-73560

    vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

    Last Modified: Aug 18, 2026
    Published: Aug 17, 2026

    CVE-2026-71486

    vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

    Last Modified: Aug 18, 2026
    Published: Aug 17, 2026

    CVE-2026-73559

    vLLM: Completion prompt lists fan out into unbounded engine requests

    Last Modified: Aug 14, 2026
    Published: Aug 13, 2026

    CVE-2026-73558

    vLLM: Cross-User Data Leak Vulnerability

    Last Modified: Aug 13, 2026
    Published: Aug 13, 2026
    Items Per Page
    Vllm-Project Vulnerabilities & Security CVEs | CVE-DB