Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vllm Project

First CVE: Jan 27, 2025Active for: 1 yearTotal CVEs: 52

Vllm Project maintains a specialized large-language-model inference engine focused on high-throughput serving of LLM workloads, with vulnerabilities tracked against a narrow product portfolio. The disclosed issues reflect the attack surface inherent to Python-based ML inference stacks; current severity, exploitation status, and exposure scope are shown alongside this summary.

FAUCET AI Generated
51
Total CVEs
Bottom 1%
25.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 91% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Vllm Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 27, 2025
17 months ago
Most Recent CVE
Jul 6, 2026
18 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (51 CVEs).

51 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-22778CRITICAL
vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an er
Feb 2, 20269.853NOYES
CVE-2026-48746CRITICAL
vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers en
Jun 22, 20269.139NONO
CVE-2026-54236MEDIUM
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778, which introduced a sanitize_message helper that strips obj
Jun 22, 20265.338NOYES
CVE-2026-56340HIGH
vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, a
Jun 20, 20268.837NONO
CVE-2026-22807CRITICAL
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules
Jan 21, 20269.837NONO
CVE-2026-54232HIGH
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusion attack through the flashinfer
Jun 22, 20268.836NONO
CVE-2026-41523HIGH
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation function loading allows any unauthent
Jun 22, 20267.534NONO
CVE-2026-5497HIGH
vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` me
Jun 11, 20267.534NONO
CVE-2026-55574HIGH
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular exp
Jul 6, 20267.533NONO
CVE-2026-54234HIGH
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative decoding workload can cause the re
Jul 6, 20267.533NONO
View all 51 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products51 CVEs
35%
43%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network49 (96.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (3.9%)
Attack Complexity
Low46 (90.2%)
High5 (9.8%)
Unknown0 (0.0%)
User Interaction
None44 (86.3%)
Unknown0 (0.0%)
Required7 (13.7%)
Privileges Required
Low22 (43.1%)
High0 (0.0%)
None29 (56.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (51 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
3.9% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vllm Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vllm Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vllm Project's Products

View all 4 CNAs →

Top CWEs