Vllm
Vendor:
First CVE: Jan 27, 2025 · Active for 1 year
51
Total CVEs
Bottom 1%
25.5
Avg CVEs / Year
Bottom 1%
7.4
Avg CVSS
Higher Avg CVSS than 88% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Vllm over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 27, 2025
17 months ago
Most Recent CVE
Jul 6, 2026
22 days ago
CVE Severity & Scoring
Vllm51 CVEs
35%
43%
18%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network49 (96.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (3.9%)
Attack Complexity
Low46 (90.2%)
High5 (9.8%)
Unknown0 (0.0%)
User Interaction
None44 (86.3%)
Unknown0 (0.0%)
Required7 (13.7%)
Privileges Required
Low22 (43.1%)
High0 (0.0%)
None29 (56.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (51 CVEs).
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22778CRITICAL vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an er | Feb 2, 2026 | 9.8 | 53 | NO | YES |
CVE-2026-48746CRITICAL vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers en | Jun 22, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-56340HIGH vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, a | Jun 20, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-22807CRITICAL vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules | Jan 21, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-54236MEDIUM vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778, which introduced a sanitize_message helper that strips obj | Jun 22, 2026 | 5.3 | 35 | NO | YES |
CVE-2026-41523HIGH vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation function loading allows any unauthent | Jun 22, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-54232HIGH vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusion attack through the flashinfer | Jun 22, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-5497HIGH vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` me | Jun 11, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-55574HIGH vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular exp | Jul 6, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-54234HIGH vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative decoding workload can cause the re | Jul 6, 2026 | 7.5 | 33 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (51 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
3.9% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (51 CVEs).
Media Mentions
Signals from CVEs in this product scope (51 CVEs).
Top CNAs Publishing CVEs For Vllm
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.6.2 | 1 | 9.8 | 1.4% | 0 | 0 |
| 0.6.0 | 1 | 9.8 | 1.3% | 0 | 0 |
| 0.11.1 | 3 | 7.3 | 0.5% | 0 | 0 |
| 0.11.0 | 1 | 7.5 | 0.5% | 0 | 0 |