CVE-2025-62164 describes a critical memory corruption vulnerability in vLLM versions 0.10.2 through 0.11.0, specifically within its Completions API endpoint. This flaw allows an attacker to trigger an out-of-bounds memory write by supplying maliciously crafted prompt embeddings, leveraging a change in PyTorch 2.8.0 that disables sparse tensor integrity checks. The vulnerability carries a high CVSS score of 8.8, indicating it can be exploited remotely with low complexity and no user interaction, potentially leading to denial-of-service or remote code execution. While no active exploitation or public exploit code has been observed, and community discussion is minimal, the high FAUCET Risk Score of 83/100 suggests significant potential impact. The issue has been patched in vLLM version 0.11.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.10.2, < 0.11.1CPE matchmatch criteria | cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:* | ||
0.11.1CPE matchmatch criteria | cpe:2.3:a:vllm:vllm:0.11.1:rc0:*:*:*:*:*:* | ||
0.11.1CPE matchmatch criteria | cpe:2.3:a:vllm:vllm:0.11.1:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.