CVE-2025-46722 describes a security and data integrity flaw in vLLM versions 0.7.0 through 0.8.x, specifically within the MultiModalHasher's image hashing method. The vulnerability arises because the hashing only uses raw pixel data, leading to potential hash collisions for images with identical pixel sequences but different dimensions. This could result in incorrect cache hits, data leakage, or other security risks. The CVSS score of 7.3 (HIGH) indicates a network-exploitable vulnerability with low attack complexity, potentially impacting confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.7.0, < 0.9.0CPE matchmatch criteria | cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.