Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-62164

32
FAUCET Score

CVE-2025-62164 describes a critical memory corruption vulnerability in vLLM versions 0.10.2 through 0.11.0, specifically within its Completions API endpoint. This flaw allows an attacker to trigger an out-of-bounds memory write by supplying maliciously crafted prompt embeddings, leveraging a change in PyTorch 2.8.0 that disables sparse tensor integrity checks. The vulnerability carries a high CVSS score of 8.8, indicating it can be exploited remotely with low complexity and no user interaction, potentially leading to denial-of-service or remote code execution. While no active exploitation or public exploit code has been observed, and community discussion is minimal, the high FAUCET Risk Score of 83/100 suggests significant potential impact. The issue has been patched in vLLM version 0.11.1.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.10.2, < 0.11.1CPE matchmatch criteria
cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*
0.11.1CPE matchmatch criteria
cpe:2.3:a:vllm:vllm:0.11.1:rc0:*:*:*:*:*:*
0.11.1CPE matchmatch criteria
cpe:2.3:a:vllm:vllm:0.11.1:rc1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.93%
Probability of exploitation in next 30 days
EPSS Percentile
56.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0093 is in the 52nd percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (17)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: vllmFixed in: 0.11.1
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-rocm-rhel9:sha256:e3b3efcdd86f60b90664a249d45918b2ac5f45bae5eed5399e310d63e878b287
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-tpu-rhel9:sha256:64796b48c68d31973a08e22c9530c39b1bc3ba9f376bbefa57643ef0fc857534
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-rocm-rhel9:sha256:c5efe40fa2a6e98d7d3d6676befff0dbbd87b2887769bb7e5856c5b0b0ada125
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-kserve-agent-rhel9:sha256:7caa5349317343219fa6a504ff80b04904df78adbc60b34a3b1951e072db513a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-kserve-controller-rhel9:sha256:1148f10bdd5624ec3ec6e2099eaadf0192bbd4a7cb5758e71b20d811354204da
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-kserve-router-rhel9:sha256:974dd5577124715f30df61d06aba22d95bc5f02103ab1b518eb517ed09284740
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-kserve-storage-initializer-rhel9:sha256:83e3b3a60fc284de9efd3dcf90cf5f744dd24cbc0a27d0d964676d93c8637750
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-cuda-rhel9:sha256:f0ab1b678e9447eae4b6b2fe5c58531aa8524133db157f196726164e4dc20492
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-aws-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-azure-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-gcp-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-vllm-cpu-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-vllm-gaudi-rhel9
redhatno patchvia redhat_api
Product: Red Hat AI Inference ServerFixed in: rhaiis/vllm-spyre-rhel9

Vendor Advisories (2)

redhatCVE-2025-62164Important

vllm: VLLM deserialization vulnerability leading to DoS and potential RCE

Nov 21, 2025
pipGHSA-mrw7-hf4f-83pfhigh

vLLM deserialization vulnerability leading to DoS and potential RCE

Nov 20, 2025

References

github.com / vllm-project/vllm/commit/58fab50d82838d5014f4a14d991fdb9352c9c84b
Patch
github.com / vllm-project/vllm/pull/27204
Issue TrackingPatchVendor Advisory
github.com / vllm-project/vllm/security/advisories/GHSA-mrw7-hf4f-83pf
Issue TrackingVendor Advisory