{"schemaVersion":"ki-abhaengigkeitsatlas/v1","dataset":"german-public-sector-ai-dependency-atlas","parserVersion":"1","generatedAt":"2026-07-20T14:37:29.537Z","trackingSince":"2026-07-18T21:20:30.334Z","source":{"codeRadar":{"dataset":"german-public-sector-ai-code-radar","generatedAt":"2026-07-20T14:36:19.763Z","parserVersion":"3","url":"https://i6eal.de/tools/ki-code-radar/"},"openCode":{"label":"openCode GitLab","url":"https://gitlab.opencode.de/"},"depsDev":{"label":"deps.dev API v3","url":"https://docs.deps.dev/api/v3/"},"osv":{"label":"OSV API","url":"https://google.github.io/osv.dev/api/"},"spdx":{"label":"SPDX License List","url":"https://spdx.org/licenses/","version":"3.28.0","releaseDate":"2026-02-20T00:00:00Z"}},"coverage":{"repositoryCount":30,"completeTreeCount":29,"incompleteTreeCount":1,"lockfileRepositoryCount":17,"sbomRepositoryCount":4,"artifactRepositoryCount":20,"resolvedRepositoryCount":29,"resolvedArtifactRepositoryCount":20,"dependencyFileCount":33,"parsedFileCount":32,"parseErrorCount":1,"unsupportedFileCount":0,"evaluatedVersionCount":4205,"metadataResolvedCount":4191,"metadataNotFoundCount":14,"osvEvaluatedVersionCount":4205,"codeRadarRepositoryCount":30},"methodology":{"componentParserSchemaVersion":"ki-dependency-atlas-components/v1","candidateBoundary":"repositories_with_exact_ai_code_evidence","resolvedVersionBoundary":"exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin","manifestRangesResolved":false,"latestVersionSubstitution":false,"containerTagsVulnerabilityChecked":false,"osvClaim":"osv_matched_observed_resolved_package_version_at_collection_time","depsDevLicenseSemantics":"spdx_expressions_as_reported_without_inferred_compatibility","providerSemantics":"package_interface_presence_not_api_configuration_procurement_or_use","generativeAiUsed":false,"scoreUsed":false,"treeEntryCeiling":2500,"fileByteCeiling":5242880,"uniqueVersionCeiling":5000,"observedFormats":["package-lock.json / npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins"]},"summary":{"repositoryCount":30,"packageCount":2831,"aiPackageCount":41,"resolvedComponentCount":7181,"resolvedVersionCount":4205,"providerExposureRepositoryCount":7,"licenseExpressionCount":57,"knownLicensePackageCount":2796,"unknownLicensePackageCount":35,"advisoryCount":572,"matchedAdvisoryRepositoryCount":25,"topPackage":{"id":"package:pypi:openai","slug":"openai-0dd26ac5","label":"OpenAI SDK","repositoryCount":18,"repositoryShare":0.6}},"kind":"paket","entity":{"id":"package:pypi:vllm","slug":"vllm-571f04fc","identity":"pypi:vllm","ecosystem":"pypi","name":"vllm","label":"vLLM","category":"model-runtime","aiRelevant":true,"provider":null,"repositoryCount":3,"occurrenceCount":3,"directRepositoryCount":0,"versionCount":3,"licenseExpressions":["Apache-2.0"],"advisoryIds":["GHSA-2pc9-4j83-qjmr","GHSA-3f6c-7fw2-ppm4","GHSA-3mwp-wvh9-7528","GHSA-3ww4-5jv9-j5gm","GHSA-4qjh-9fv9-r85r","GHSA-4r2x-xpjr-7cvv","GHSA-5jv2-g5wq-cmr4","GHSA-69j4-grxj-j64p","GHSA-6c4r-fmh3-7rh8","GHSA-6fvq-23cw-5628","GHSA-6pr9-rp53-2pmc","GHSA-6qc9-v4r8-22xg","GHSA-7972-pg2x-xr59","GHSA-7h4p-rffg-7823","GHSA-8fr4-5q9j-m8gm","GHSA-8jr5-v98p-w75m","GHSA-94f4-hr76-p5j6","GHSA-98f3-hwg4-4rf7","GHSA-9hcf-v7m4-6m2j","GHSA-9pcc-gvx5-r5wm","GHSA-c65p-x677-fgj6","GHSA-grg2-63fw-f2qr","GHSA-hgg8-fqqc-vfmw","GHSA-hpv8-x276-m59f","GHSA-j828-28rj-hfhp","GHSA-mcmc-2m55-j8jj","GHSA-mrw7-hf4f-83pf","GHSA-pmqf-x6x8-p7qw","GHSA-pq5c-rjhq-qp7p","GHSA-q8gq-377p-jq3r","GHSA-qh4c-xf7m-gxfc","GHSA-rwxx-mrjm-wc2m","GHSA-rxc4-3w6r-4v47","GHSA-vrq3-r879-7m65","GHSA-w6q7-j642-7c25","GHSA-wr9h-g72x-mwhm","GHSA-x368-4g9h-fvv4","PYSEC-2026-227","PYSEC-2026-2302"],"advisoryCount":39,"verifiedAttestation":false,"repositories":[{"id":"opencode:7674","slug":"opencode-7674","name":"Coding Agent Usage Simulation","pathWithNamespace":"uba-ki-lab/coding-agent-usage-simulation","versions":["0.11.0"],"evidenceCount":1},{"id":"opencode:10787","slug":"opencode-10787","name":"LLM Questionnaire Benchmarking Framework","pathWithNamespace":"uba-ki-lab/llm-questionnaire-benchmarking-framework","versions":["0.10.1.1"],"evidenceCount":1},{"id":"opencode:5012","slug":"opencode-5012","name":"LLM Testframework","pathWithNamespace":"uba-ki-lab/llm-testframework","versions":["0.8.5.post1"],"evidenceCount":1}],"versions":[{"version":"0.8.5.post1","repositoryCount":1,"occurrenceCount":1,"ageDays":443,"advisoryIds":["GHSA-3f6c-7fw2-ppm4","GHSA-3mwp-wvh9-7528","GHSA-3ww4-5jv9-j5gm","GHSA-4qjh-9fv9-r85r","GHSA-4r2x-xpjr-7cvv","GHSA-5jv2-g5wq-cmr4","GHSA-69j4-grxj-j64p","GHSA-6c4r-fmh3-7rh8","GHSA-6fvq-23cw-5628","GHSA-6pr9-rp53-2pmc","GHSA-6qc9-v4r8-22xg","GHSA-7h4p-rffg-7823","GHSA-8fr4-5q9j-m8gm","GHSA-94f4-hr76-p5j6","GHSA-98f3-hwg4-4rf7","GHSA-9hcf-v7m4-6m2j","GHSA-9pcc-gvx5-r5wm","GHSA-c65p-x677-fgj6","GHSA-grg2-63fw-f2qr","GHSA-hgg8-fqqc-vfmw","GHSA-hpv8-x276-m59f","GHSA-j828-28rj-hfhp","GHSA-pmqf-x6x8-p7qw","GHSA-pq5c-rjhq-qp7p","GHSA-q8gq-377p-jq3r","GHSA-qh4c-xf7m-gxfc","GHSA-rwxx-mrjm-wc2m","GHSA-rxc4-3w6r-4v47","GHSA-vrq3-r879-7m65","GHSA-w6q7-j642-7c25","GHSA-wr9h-g72x-mwhm","GHSA-x368-4g9h-fvv4","PYSEC-2026-227","PYSEC-2026-2302"],"metadata":{"state":"resolved","checkedAt":"2026-07-20T03:19:50.101Z","publishedAt":"2025-05-02T22:31:02Z","deprecated":false,"deprecatedReason":null,"licenses":["Apache-2.0"],"advisoryIds":["GHSA-3f6c-7fw2-ppm4","GHSA-3mwp-wvh9-7528","GHSA-3ww4-5jv9-j5gm","GHSA-4qjh-9fv9-r85r","GHSA-4r2x-xpjr-7cvv","GHSA-5jv2-g5wq-cmr4","GHSA-69j4-grxj-j64p","GHSA-6c4r-fmh3-7rh8","GHSA-6fvq-23cw-5628","GHSA-6pr9-rp53-2pmc","GHSA-6qc9-v4r8-22xg","GHSA-7h4p-rffg-7823","GHSA-8fr4-5q9j-m8gm","GHSA-94f4-hr76-p5j6","GHSA-98f3-hwg4-4rf7","GHSA-9hcf-v7m4-6m2j","GHSA-9pcc-gvx5-r5wm","GHSA-c65p-x677-fgj6","GHSA-grg2-63fw-f2qr","GHSA-hgg8-fqqc-vfmw","GHSA-hpv8-x276-m59f","GHSA-j828-28rj-hfhp","GHSA-pmqf-x6x8-p7qw","GHSA-pq5c-rjhq-qp7p","GHSA-q8gq-377p-jq3r","GHSA-qh4c-xf7m-gxfc","GHSA-rwxx-mrjm-wc2m","GHSA-rxc4-3w6r-4v47","GHSA-vrq3-r879-7m65","GHSA-w6q7-j642-7c25","GHSA-wr9h-g72x-mwhm","GHSA-x368-4g9h-fvv4","PYSEC-2025-43","PYSEC-2025-50","PYSEC-2025-53","PYSEC-2025-54","PYSEC-2025-55","PYSEC-2026-143","PYSEC-2026-144","PYSEC-2026-2011","PYSEC-2026-2012","PYSEC-2026-2013","PYSEC-2026-2015","PYSEC-2026-2017","PYSEC-2026-2019","PYSEC-2026-2020","PYSEC-2026-2021","PYSEC-2026-2023","PYSEC-2026-2026","PYSEC-2026-226","PYSEC-2026-227","PYSEC-2026-2298","PYSEC-2026-2299","PYSEC-2026-2300","PYSEC-2026-2301","PYSEC-2026-2302","PYSEC-2026-2304","PYSEC-2026-2306","PYSEC-2026-3403","PYSEC-2026-3404","PYSEC-2026-3405","PYSEC-2026-3407","PYSEC-2026-3408","PYSEC-2026-3409","PYSEC-2026-565"],"links":[{"label":"SOURCE_REPO","url":"https://github.com/vllm-project/vllm"},{"label":"HOMEPAGE","url":"https://github.com/vllm-project/vllm"},{"label":"DOCUMENTATION","url":"https://vllm.readthedocs.io/en/latest/"}],"relatedProjects":[{"id":"github.com/vllm-project/vllm","relationType":"SOURCE_REPO","relationProvenance":"UNVERIFIED_METADATA"}],"attestations":[],"verifiedAttestation":false,"projectStatus":"active"}},{"version":"0.10.1.1","repositoryCount":1,"occurrenceCount":1,"ageDays":333,"advisoryIds":["GHSA-2pc9-4j83-qjmr","GHSA-3f6c-7fw2-ppm4","GHSA-3mwp-wvh9-7528","GHSA-3ww4-5jv9-j5gm","GHSA-4r2x-xpjr-7cvv","GHSA-5jv2-g5wq-cmr4","GHSA-69j4-grxj-j64p","GHSA-6c4r-fmh3-7rh8","GHSA-6fvq-23cw-5628","GHSA-6pr9-rp53-2pmc","GHSA-7972-pg2x-xr59","GHSA-7h4p-rffg-7823","GHSA-8fr4-5q9j-m8gm","GHSA-94f4-hr76-p5j6","GHSA-98f3-hwg4-4rf7","GHSA-grg2-63fw-f2qr","GHSA-hgg8-fqqc-vfmw","GHSA-hpv8-x276-m59f","GHSA-pmqf-x6x8-p7qw","GHSA-pq5c-rjhq-qp7p","GHSA-q8gq-377p-jq3r","GHSA-qh4c-xf7m-gxfc","GHSA-rwxx-mrjm-wc2m","GHSA-wr9h-g72x-mwhm","GHSA-x368-4g9h-fvv4","PYSEC-2026-227","PYSEC-2026-2302"],"metadata":{"state":"resolved","checkedAt":"2026-07-20T03:19:50.101Z","publishedAt":"2025-08-20T23:17:09Z","deprecated":false,"deprecatedReason":null,"licenses":["Apache-2.0"],"advisoryIds":["GHSA-2pc9-4j83-qjmr","GHSA-3f6c-7fw2-ppm4","GHSA-3mwp-wvh9-7528","GHSA-3ww4-5jv9-j5gm","GHSA-4r2x-xpjr-7cvv","GHSA-5jv2-g5wq-cmr4","GHSA-69j4-grxj-j64p","GHSA-6c4r-fmh3-7rh8","GHSA-6fvq-23cw-5628","GHSA-6pr9-rp53-2pmc","GHSA-7972-pg2x-xr59","GHSA-7h4p-rffg-7823","GHSA-8fr4-5q9j-m8gm","GHSA-94f4-hr76-p5j6","GHSA-98f3-hwg4-4rf7","GHSA-grg2-63fw-f2qr","GHSA-hgg8-fqqc-vfmw","GHSA-hpv8-x276-m59f","GHSA-pmqf-x6x8-p7qw","GHSA-pq5c-rjhq-qp7p","GHSA-q8gq-377p-jq3r","GHSA-qh4c-xf7m-gxfc","GHSA-rwxx-mrjm-wc2m","GHSA-wr9h-g72x-mwhm","GHSA-x368-4g9h-fvv4","PYSEC-2026-143","PYSEC-2026-144","PYSEC-2026-2010","PYSEC-2026-2011","PYSEC-2026-2012","PYSEC-2026-2013","PYSEC-2026-2015","PYSEC-2026-2019","PYSEC-2026-2020","PYSEC-2026-2026","PYSEC-2026-226","PYSEC-2026-227","PYSEC-2026-2297","PYSEC-2026-2298","PYSEC-2026-2299","PYSEC-2026-2300","PYSEC-2026-2301","PYSEC-2026-2302","PYSEC-2026-2304","PYSEC-2026-2306","PYSEC-2026-3403","PYSEC-2026-3404","PYSEC-2026-3405","PYSEC-2026-3407","PYSEC-2026-3408","PYSEC-2026-3409","PYSEC-2026-565"],"links":[{"label":"SOURCE_REPO","url":"https://github.com/vllm-project/vllm"},{"label":"HOMEPAGE","url":"https://github.com/vllm-project/vllm"},{"label":"DOCUMENTATION","url":"https://docs.vllm.ai/en/latest/"}],"relatedProjects":[{"id":"github.com/vllm-project/vllm","relationType":"SOURCE_REPO","relationProvenance":"UNVERIFIED_METADATA"}],"attestations":[],"verifiedAttestation":false,"projectStatus":"active"}},{"version":"0.11.0","repositoryCount":1,"occurrenceCount":1,"ageDays":289,"advisoryIds":["GHSA-2pc9-4j83-qjmr","GHSA-3mwp-wvh9-7528","GHSA-3ww4-5jv9-j5gm","GHSA-4r2x-xpjr-7cvv","GHSA-5jv2-g5wq-cmr4","GHSA-69j4-grxj-j64p","GHSA-6c4r-fmh3-7rh8","GHSA-6pr9-rp53-2pmc","GHSA-7972-pg2x-xr59","GHSA-7h4p-rffg-7823","GHSA-8fr4-5q9j-m8gm","GHSA-8jr5-v98p-w75m","GHSA-94f4-hr76-p5j6","GHSA-98f3-hwg4-4rf7","GHSA-grg2-63fw-f2qr","GHSA-hgg8-fqqc-vfmw","GHSA-hpv8-x276-m59f","GHSA-mcmc-2m55-j8jj","GHSA-mrw7-hf4f-83pf","GHSA-pmqf-x6x8-p7qw","GHSA-pq5c-rjhq-qp7p","GHSA-q8gq-377p-jq3r","GHSA-qh4c-xf7m-gxfc","GHSA-rwxx-mrjm-wc2m","GHSA-x368-4g9h-fvv4","PYSEC-2026-227","PYSEC-2026-2302"],"metadata":{"state":"resolved","checkedAt":"2026-07-20T03:19:50.101Z","publishedAt":"2025-10-04T01:39:32Z","deprecated":false,"deprecatedReason":null,"licenses":["Apache-2.0"],"advisoryIds":["GHSA-2pc9-4j83-qjmr","GHSA-3mwp-wvh9-7528","GHSA-3ww4-5jv9-j5gm","GHSA-4r2x-xpjr-7cvv","GHSA-5jv2-g5wq-cmr4","GHSA-69j4-grxj-j64p","GHSA-6c4r-fmh3-7rh8","GHSA-6pr9-rp53-2pmc","GHSA-7972-pg2x-xr59","GHSA-7h4p-rffg-7823","GHSA-8fr4-5q9j-m8gm","GHSA-8jr5-v98p-w75m","GHSA-94f4-hr76-p5j6","GHSA-98f3-hwg4-4rf7","GHSA-grg2-63fw-f2qr","GHSA-hgg8-fqqc-vfmw","GHSA-hpv8-x276-m59f","GHSA-mcmc-2m55-j8jj","GHSA-mrw7-hf4f-83pf","GHSA-pmqf-x6x8-p7qw","GHSA-pq5c-rjhq-qp7p","GHSA-q8gq-377p-jq3r","GHSA-qh4c-xf7m-gxfc","GHSA-rwxx-mrjm-wc2m","GHSA-x368-4g9h-fvv4","PYSEC-2026-143","PYSEC-2026-144","PYSEC-2026-2010","PYSEC-2026-2012","PYSEC-2026-2015","PYSEC-2026-2018","PYSEC-2026-2019","PYSEC-2026-2020","PYSEC-2026-226","PYSEC-2026-227","PYSEC-2026-2297","PYSEC-2026-2298","PYSEC-2026-2299","PYSEC-2026-2300","PYSEC-2026-2301","PYSEC-2026-2302","PYSEC-2026-2304","PYSEC-2026-2306","PYSEC-2026-250","PYSEC-2026-3403","PYSEC-2026-3404","PYSEC-2026-3405","PYSEC-2026-3406","PYSEC-2026-3407","PYSEC-2026-3408","PYSEC-2026-3409","PYSEC-2026-565"],"links":[{"label":"SOURCE_REPO","url":"https://github.com/vllm-project/vllm"},{"label":"HOMEPAGE","url":"https://github.com/vllm-project/vllm"},{"label":"DOCUMENTATION","url":"https://docs.vllm.ai/en/latest/"}],"relatedProjects":[{"id":"github.com/vllm-project/vllm","relationType":"SOURCE_REPO","relationProvenance":"UNVERIFIED_METADATA"}],"attestations":[],"verifiedAttestation":false,"projectStatus":"active"}}]},"evidence":{"occurrences":[{"id":"component:6ba2ebd7c7693588ea5eb986","repositoryId":"opencode:7674","repositorySlug":"opencode-7674","repositoryName":"Coding Agent Usage Simulation","repositoryPathWithNamespace":"uba-ki-lab/coding-agent-usage-simulation","ecosystem":"pypi","name":"vllm","identity":"pypi:vllm","version":"0.11.0","versionKey":"pypi:vllm@0.11.0","direct":null,"development":null,"sourceKind":"uv-lock","filePath":"uv.lock","blobSha":"1b1464cf01496db34285bf91f7841aed50559816","sourceUrl":"https://gitlab.opencode.de/uba-ki-lab/coding-agent-usage-simulation/-/blob/fe8ab81af4926a34c6cf1f3a807ffeda2b398f32/uv.lock","commitSha":"fe8ab81af4926a34c6cf1f3a807ffeda2b398f32"},{"id":"component:5f3e8a1c09e465d3492436ec","repositoryId":"opencode:10787","repositorySlug":"opencode-10787","repositoryName":"LLM Questionnaire Benchmarking Framework","repositoryPathWithNamespace":"uba-ki-lab/llm-questionnaire-benchmarking-framework","ecosystem":"pypi","name":"vllm","identity":"pypi:vllm","version":"0.10.1.1","versionKey":"pypi:vllm@0.10.1.1","direct":null,"development":null,"sourceKind":"uv-lock","filePath":"uv.lock","blobSha":"1b55661fee93d4733461df8e9c2b491b9205aac2","sourceUrl":"https://gitlab.opencode.de/uba-ki-lab/llm-questionnaire-benchmarking-framework/-/blob/4e12ee9f3b0b6fdc77fe21cb89e6cfac17dc6ebd/uv.lock","commitSha":"4e12ee9f3b0b6fdc77fe21cb89e6cfac17dc6ebd"},{"id":"component:27f212d44914467d2a5b2c19","repositoryId":"opencode:5012","repositorySlug":"opencode-5012","repositoryName":"LLM Testframework","repositoryPathWithNamespace":"uba-ki-lab/llm-testframework","ecosystem":"pypi","name":"vllm","identity":"pypi:vllm","version":"0.8.5.post1","versionKey":"pypi:vllm@0.8.5.post1","direct":null,"development":null,"sourceKind":"uv-lock","filePath":"uv.lock","blobSha":"b4c29eab16a40db016821e4ea567956048a046ea","sourceUrl":"https://gitlab.opencode.de/uba-ki-lab/llm-testframework/-/blob/e8d6e99a1fa63b264e727acb553ed9b1499789b1/uv.lock","commitSha":"e8d6e99a1fa63b264e727acb553ed9b1499789b1"}],"occurrenceCount":3},"related":{"repositories":[{"id":"opencode:7674","slug":"opencode-7674","name":"Coding Agent Usage Simulation","pathWithNamespace":"uba-ki-lab/coding-agent-usage-simulation","versions":["0.11.0"],"evidenceCount":1},{"id":"opencode:10787","slug":"opencode-10787","name":"LLM Questionnaire Benchmarking Framework","pathWithNamespace":"uba-ki-lab/llm-questionnaire-benchmarking-framework","versions":["0.10.1.1"],"evidenceCount":1},{"id":"opencode:5012","slug":"opencode-5012","name":"LLM Testframework","pathWithNamespace":"uba-ki-lab/llm-testframework","versions":["0.8.5.post1"],"evidenceCount":1}],"vulnerabilities":[{"id":"GHSA-2pc9-4j83-qjmr","slug":"ghsa-2pc9-4j83-qjmr-6e2eb21d","dossier":false,"summary":"vLLM affected by RCE via auto_map dynamic module loading during model initialization","aliases":["CVE-2026-22807","PYSEC-2026-2010"],"sourceIds":["GHSA-2pc9-4j83-qjmr","PYSEC-2026-2010"],"published":"2026-01-21T16:12:54Z","modified":"2026-07-17T16:30:29.025047931Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-2pc9-4j83-qjmr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22807"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/32194"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/78d13ea9de4b1ce5e4d8a5af9738fea71fb024e5"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22807.json"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/releases/tag/v0.14.0"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2010.yaml"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2pc9-4j83-qjmr"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2431865"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-22807"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:5119"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3782"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3713"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3462"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-3f6c-7fw2-ppm4","slug":"ghsa-3f6c-7fw2-ppm4-735443b9","dossier":false,"summary":"vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class","aliases":["CVE-2025-6242","PYSEC-2026-2011"],"sourceIds":["GHSA-3f6c-7fw2-ppm4","PYSEC-2026-2011"],"published":"2025-10-07T22:14:15Z","modified":"2026-07-07T17:57:19.957237175Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-3f6c-7fw2-ppm4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6242"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/9d9a2b77f19f68262d5e469c4e82c0f6365ad72d"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2025-6242"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2373716"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3f6c-7fw2-ppm4"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-3mwp-wvh9-7528","slug":"ghsa-3mwp-wvh9-7528-9c78ec85","dossier":false,"summary":"vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server","aliases":["CVE-2026-34756","PYSEC-2026-2298"],"sourceIds":["GHSA-3mwp-wvh9-7528","PYSEC-2026-2298"],"published":"2026-04-03T15:35:48Z","modified":"2026-07-17T16:30:29.032335074Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"FIX","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-3mwp-wvh9-7528"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34756"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/pull/37952"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/b111f8a61f100fdca08706f41f29ef3548de7380"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36005"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36006"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-34756"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2455425"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2298.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34756.json"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-3ww4-5jv9-j5gm","slug":"ghsa-3ww4-5jv9-j5gm-a5372bc1","dossier":false,"summary":"vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors","aliases":["CVE-2026-47155","PYSEC-2026-2301"],"sourceIds":["GHSA-3ww4-5jv9-j5gm","PYSEC-2026-2301"],"published":"2026-06-10T17:11:38Z","modified":"2026-07-17T16:30:30.495129102Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-3ww4-5jv9-j5gm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47155"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/pull/42616"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/d26a28ab033697f55a1414b5b0435de7cd6045b6"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2301.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"ADVISORY","url":"https://huntr.com/bounties/3f1e24c0-87d2-4f6c-a705-820f380879ac"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-4qjh-9fv9-r85r","slug":"ghsa-4qjh-9fv9-r85r-e1501317","dossier":false,"summary":"Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching","aliases":["CVE-2025-46570","PYSEC-2025-53"],"sourceIds":["GHSA-4qjh-9fv9-r85r","PYSEC-2025-53"],"published":"2025-05-28T18:02:24Z","modified":"2026-02-04T03:48:23.274649Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-4qjh-9fv9-r85r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-46570"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/pull/17045"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/77073c77bc2006eb80ea6d5128f076f5e6c6f54f"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-53.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-4r2x-xpjr-7cvv","slug":"ghsa-4r2x-xpjr-7cvv-b37b8fa2","dossier":false,"summary":"vLLM has RCE In Video Processing","aliases":["CVE-2026-22778","PYSEC-2026-565"],"sourceIds":["GHSA-4r2x-xpjr-7cvv","PYSEC-2026-565"],"published":"2026-02-02T17:43:45Z","modified":"2026-07-17T16:30:29.022952299Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-4r2x-xpjr-7cvv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22778"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/32319"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/31987"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22778.json"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/releases/tag/v0.14.1"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-565.yaml"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4r2x-xpjr-7cvv"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2436113"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-22778"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3782"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3713"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3462"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3461"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-5jv2-g5wq-cmr4","slug":"ghsa-5jv2-g5wq-cmr4-b1c3983f","dossier":false,"summary":"vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving","aliases":["CVE-2026-53923","PYSEC-2026-3403"],"sourceIds":["GHSA-5jv2-g5wq-cmr4","PYSEC-2026-3403"],"published":"2026-06-17T14:03:11Z","modified":"2026-07-17T16:30:30.538194678Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-5jv2-g5wq-cmr4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53923"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/44971"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/f219788f91952827132fa4fdf916427cd20d225e"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5jv2-g5wq-cmr4"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3403.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-69j4-grxj-j64p","slug":"ghsa-69j4-grxj-j64p-ff78c10b","dossier":false,"summary":"vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`","aliases":["CVE-2025-62426","PYSEC-2026-2012"],"sourceIds":["GHSA-69j4-grxj-j64p","PYSEC-2026-2012"],"published":"2025-11-20T21:26:24Z","modified":"2026-07-17T16:30:30.603743359Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-69j4-grxj-j64p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62426"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/27205"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/3ada34f9cb4d1af763fdfa3b481862a93eb6bd2b"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-69j4-grxj-j64p"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2012.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/blob/2a6dc67eb520ddb9c4138d8b35ed6fe6226997fb/vllm/entrypoints/chat_utils.py#L1602-L1610"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/blob/2a6dc67eb520ddb9c4138d8b35ed6fe6226997fb/vllm/entrypoints/openai/serving_engine.py#L809-L814"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-6c4r-fmh3-7rh8","slug":"ghsa-6c4r-fmh3-7rh8-a82d795c","dossier":false,"summary":"vLLM: Processing differential in multi-channel audio downmixing enables hidden-input/moderation bypass for audio models","aliases":["CVE-2026-34760","PYSEC-2026-2299"],"sourceIds":["GHSA-6c4r-fmh3-7rh8","PYSEC-2026-2299"],"published":"2026-04-02T20:16:25.437Z","modified":"2026-07-17T17:00:52.155049383Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-6c4r-fmh3-7rh8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34760"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/pull/37058"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/c7f98b4d0a63b32ed939e2b6dfaa8a626e9b46c4"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2299.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/releases/tag/v0.18.0"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-6fvq-23cw-5628","slug":"ghsa-6fvq-23cw-5628-8eb01b7c","dossier":false,"summary":"vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server","aliases":["CVE-2025-61620","PYSEC-2026-2013"],"sourceIds":["GHSA-6fvq-23cw-5628","PYSEC-2026-2013"],"published":"2025-10-07T21:35:22Z","modified":"2026-07-07T17:56:38.020494737Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-6fvq-23cw-5628"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/25794"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/7977e5027c2250a4abc1f474c5619c40b4e5682f"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6fvq-23cw-5628"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61620"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-6pr9-rp53-2pmc","slug":"ghsa-6pr9-rp53-2pmc-1471f1e7","dossier":false,"summary":"vLLM: OOM Denial of Service via Audio Decompression Bomb","aliases":["CVE-2026-54233","PYSEC-2026-3404"],"sourceIds":["GHSA-6pr9-rp53-2pmc","PYSEC-2026-3404"],"published":"2026-06-17T14:06:22Z","modified":"2026-07-17T16:45:18.929893807Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-6pr9-rp53-2pmc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54233"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/44970"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/1b1359c33269446f13c05da9a90c25174cbea590"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6pr9-rp53-2pmc"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3404.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/releases/tag/v0.23.1rc0"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-6qc9-v4r8-22xg","slug":"ghsa-6qc9-v4r8-22xg-0e64781f","dossier":false,"summary":"vLLM DOS: Remotely kill vllm over http with invalid JSON schema","aliases":["CVE-2025-48942","PYSEC-2025-54"],"sourceIds":["GHSA-6qc9-v4r8-22xg","PYSEC-2025-54"],"published":"2025-05-28T19:41:53Z","modified":"2026-02-04T02:16:15.150519Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-6qc9-v4r8-22xg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48942"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/issues/17248"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/pull/17623"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/08bf7840780980c7568c573c70a6a8db94fd45ff"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-54.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-7972-pg2x-xr59","slug":"ghsa-7972-pg2x-xr59-8de5a611","dossier":false,"summary":"vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out","aliases":["CVE-2026-27893","PYSEC-2026-2297"],"sourceIds":["GHSA-7972-pg2x-xr59","PYSEC-2026-2297"],"published":"2026-03-27T00:16:22.333Z","modified":"2026-07-17T16:30:29.029310389Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-7972-pg2x-xr59"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27893"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/pull/36192"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/00bd08edeee5dd4d4c13277c0114a464011acf72"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27893.json"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2297.yaml"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2452055"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-27893"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:8748"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:8747"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:8746"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24977"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19725"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19724"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:10140"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:10141"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19712"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-7h4p-rffg-7823","slug":"ghsa-7h4p-rffg-7823-c840dc90","dossier":false,"summary":"vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels","aliases":["CVE-2026-54235","PYSEC-2026-3405"],"sourceIds":["GHSA-7h4p-rffg-7823","PYSEC-2026-3405"],"published":"2026-06-17T14:02:22Z","modified":"2026-07-17T16:45:18.824754082Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-7h4p-rffg-7823"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54235"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/45116"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/d598d239737cfa37bcfcb98886ec3f3557fc7198"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7h4p-rffg-7823"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3405.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-8fr4-5q9j-m8gm","slug":"ghsa-8fr4-5q9j-m8gm-9a59ba60","dossier":false,"summary":"vLLM vulnerable to remote code execution via transformers_utils/get_config","aliases":["CVE-2025-66448","PYSEC-2026-2015"],"sourceIds":["GHSA-8fr4-5q9j-m8gm","PYSEC-2026-2015"],"published":"2025-12-02T17:34:16Z","modified":"2026-07-17T16:30:30.600907369Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-8fr4-5q9j-m8gm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66448"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/28126"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/ffb08379d8870a1a81ba82b72797f196838d0c86"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8fr4-5q9j-m8gm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2015.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-8jr5-v98p-w75m","slug":"ghsa-8jr5-v98p-w75m-be5fb565","dossier":false,"summary":"vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations","aliases":["CVE-2026-12491","PYSEC-2026-3406"],"sourceIds":["GHSA-8jr5-v98p-w75m","PYSEC-2026-3406"],"published":"2026-06-17T14:02:42Z","modified":"2026-07-17T16:45:18.723841391Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-8jr5-v98p-w75m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12491"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/44974"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/cf1c90672404548aa3bc51f92c4745576a65ee26"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-12491"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2489786"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8jr5-v98p-w75m"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3406.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.11.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-94f4-hr76-p5j6","slug":"ghsa-94f4-hr76-p5j6-34e6691e","dossier":false,"summary":"vLLM: OpenAI auth bypass","aliases":["CVE-2026-48746","PYSEC-2026-226"],"sourceIds":["GHSA-94f4-hr76-p5j6","PYSEC-2026-226"],"published":"2026-06-16T17:36:41Z","modified":"2026-07-17T16:30:30.589294814Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48746"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/pull/43426"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:30088"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:30089"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:36005"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:36006"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-48746"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491581"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-226.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48746.json"},{"type":"ADVISORY","url":"https://x41-dsec.de/lab/advisories/x41-2026-002-starlette"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-98f3-hwg4-4rf7","slug":"ghsa-98f3-hwg4-4rf7-af876537","dossier":false,"summary":"vllm has Improper Resource Shutdown or Release","aliases":["CVE-2026-9540","PYSEC-2026-3407"],"sourceIds":["GHSA-98f3-hwg4-4rf7","PYSEC-2026-3407"],"published":"2026-05-26T15:32:10Z","modified":"2026-07-13T16:43:04.792575152Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9540"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/issues/37343"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/37594"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://ingero.io/debugging-vllm-latency-minimax-ollama-mcp"},{"type":"WEB","url":"https://vuldb.com/submit/814645"},{"type":"WEB","url":"https://vuldb.com/vuln/365601"},{"type":"WEB","url":"https://vuldb.com/vuln/365601/cti"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-98f3-hwg4-4rf7"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-9hcf-v7m4-6m2j","slug":"ghsa-9hcf-v7m4-6m2j-d85c17a2","dossier":false,"summary":"vLLM allows clients to crash the openai server with invalid regex","aliases":["CVE-2025-48943","PYSEC-2025-55"],"sourceIds":["GHSA-9hcf-v7m4-6m2j","PYSEC-2025-55"],"published":"2025-05-28T19:42:12Z","modified":"2026-02-04T02:59:05.360205Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-9hcf-v7m4-6m2j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48943"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/issues/17313"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/pull/17623"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/08bf7840780980c7568c573c70a6a8db94fd45ff"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-55.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-9pcc-gvx5-r5wm","slug":"ghsa-9pcc-gvx5-r5wm-4c73fdb6","dossier":false,"summary":"Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration","aliases":["CVE-2025-30165","PYSEC-2026-2017"],"sourceIds":["GHSA-9pcc-gvx5-r5wm","PYSEC-2026-2017"],"published":"2025-05-06T16:38:35Z","modified":"2026-07-17T16:30:32.007556436Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-9pcc-gvx5-r5wm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30165"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9pcc-gvx5-r5wm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2017.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/blob/c21b99b91241409c2fdf9f3f8c542e8748b317be/vllm/distributed/device_communicators/shm_broadcast.py#L295-L301"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/blob/c21b99b91241409c2fdf9f3f8c542e8748b317be/vllm/distributed/device_communicators/shm_broadcast.py#L468-L470"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-c65p-x677-fgj6","slug":"ghsa-c65p-x677-fgj6-db33633a","dossier":false,"summary":"vLLM has a Weakness in MultiModalHasher Image Hashing Implementation","aliases":["CVE-2025-46722","PYSEC-2025-43"],"sourceIds":["GHSA-c65p-x677-fgj6","PYSEC-2025-43"],"published":"2025-05-28T18:03:41Z","modified":"2026-02-04T03:00:21.842092Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-c65p-x677-fgj6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-46722"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/17378"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/99404f53c72965b41558aceb1bc2380875f5d848"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-43.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-grg2-63fw-f2qr","slug":"ghsa-grg2-63fw-f2qr-b9670d50","dossier":false,"summary":"vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions","aliases":["CVE-2026-22773","PYSEC-2026-143"],"sourceIds":["GHSA-grg2-63fw-f2qr","PYSEC-2026-143"],"published":"2026-01-10T07:16:03.527Z","modified":"2026-06-08T20:00:15.842086505Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-grg2-63fw-f2qr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22773"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/29881"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/0ec84221718d920c3f46da879cc354f94b8fb59e"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-143.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-hgg8-fqqc-vfmw","slug":"ghsa-hgg8-fqqc-vfmw-ba9b1162","dossier":false,"summary":"vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router","aliases":["CVE-2026-54236","PYSEC-2026-3408"],"sourceIds":["GHSA-hgg8-fqqc-vfmw","PYSEC-2026-3408"],"published":"2026-06-17T14:04:09Z","modified":"2026-07-20T13:45:32.249353382Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-hgg8-fqqc-vfmw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54236"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/45119"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/94923629729381d7f7c9efde72071a2441f7fd82"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hgg8-fqqc-vfmw"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3408.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-hpv8-x276-m59f","slug":"ghsa-hpv8-x276-m59f-6a62e8b6","dossier":false,"summary":"vLLM Vulnerable to Remote DoS via Special-Token Placeholders","aliases":["CVE-2026-44222","PYSEC-2026-3409"],"sourceIds":["GHSA-hpv8-x276-m59f","PYSEC-2026-3409"],"published":"2026-05-05T22:21:41Z","modified":"2026-07-17T16:30:29.072224452Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-hpv8-x276-m59f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44222"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/issues/32656"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hpv8-x276-m59f"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3409.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-j828-28rj-hfhp","slug":"ghsa-j828-28rj-hfhp-e66dafb9","dossier":false,"summary":"vLLM vulnerable to Regular Expression Denial of Service","aliases":["CVE-2025-71379"],"sourceIds":["GHSA-j828-28rj-hfhp"],"published":"2025-05-28T17:50:06Z","modified":"2026-07-08T07:35:38.046987158Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-j828-28rj-hfhp"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/18454"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/4fc1bf813ad80172c1db31264beaef7d93fe0601"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-mcmc-2m55-j8jj","slug":"ghsa-mcmc-2m55-j8jj-ea2fc7d3","dossier":false,"summary":"vLLM introduced enhanced protection for CVE-2025-62164","aliases":["CVE-2026-56340","PYSEC-2026-250"],"sourceIds":["GHSA-mcmc-2m55-j8jj","PYSEC-2026-250"],"published":"2026-01-08T21:47:43Z","modified":"2026-06-27T11:26:32.894007747Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-mcmc-2m55-j8jj"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/30649"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/vllm-denial-of-service-via-unvalidated-multimodal-embeddings"}],"versionKeys":["pypi:vllm@0.11.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-mrw7-hf4f-83pf","slug":"ghsa-mrw7-hf4f-83pf-125f2ed3","dossier":false,"summary":"vLLM deserialization vulnerability leading to DoS and potential RCE","aliases":["CVE-2025-62164","PYSEC-2026-2018"],"sourceIds":["GHSA-mrw7-hf4f-83pf","PYSEC-2026-2018"],"published":"2025-11-20T20:59:34Z","modified":"2026-07-17T16:30:30.638326686Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-mrw7-hf4f-83pf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62164"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/27204"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/58fab50d82838d5014f4a14d991fdb9352c9c84b"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mrw7-hf4f-83pf"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2018.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.11.0"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-pmqf-x6x8-p7qw","slug":"ghsa-pmqf-x6x8-p7qw-b2778e4b","dossier":false,"summary":"vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs","aliases":["CVE-2025-62372","PYSEC-2026-2019"],"sourceIds":["GHSA-pmqf-x6x8-p7qw","PYSEC-2026-2019"],"published":"2025-11-20T21:23:29Z","modified":"2026-07-17T16:30:32.010515304Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-pmqf-x6x8-p7qw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62372"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/27204"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/6613"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/58fab50d82838d5014f4a14d991fdb9352c9c84b"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pmqf-x6x8-p7qw"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2019.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-pq5c-rjhq-qp7p","slug":"ghsa-pq5c-rjhq-qp7p-741b6a4f","dossier":false,"summary":"vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing","aliases":["CVE-2026-34755","PYSEC-2026-144"],"sourceIds":["GHSA-pq5c-rjhq-qp7p","PYSEC-2026-144"],"published":"2026-04-03T21:51:35Z","modified":"2026-07-17T16:30:29.016474105Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"FIX","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-pq5c-rjhq-qp7p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34755"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/38636"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/58ee61422169ce17e08248f8efa1e9df434fe395"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:36005"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:36006"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-34755"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2455403"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-144.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34755.json"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-q8gq-377p-jq3r","slug":"ghsa-q8gq-377p-jq3r-b6095d17","dossier":false,"summary":"vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution","aliases":["CVE-2026-41523","PYSEC-2026-2300"],"sourceIds":["GHSA-q8gq-377p-jq3r","PYSEC-2026-2300"],"published":"2026-06-16T17:34:49Z","modified":"2026-07-17T16:30:30.544440776Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-q8gq-377p-jq3r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41523"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/b3c7ffcab82c2439726f8cb213800f6f38c023d3"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36005"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36006"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-41523"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491582"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2300.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"ADVISORY","url":"https://huntr.com/bounties/dcb05b04-e625-41e7-adbc-bbae0cc2d64c"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41523.json"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-qh4c-xf7m-gxfc","slug":"ghsa-qh4c-xf7m-gxfc-81424acf","dossier":false,"summary":"vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector","aliases":["CVE-2026-24779","PYSEC-2026-2020"],"sourceIds":["GHSA-qh4c-xf7m-gxfc","PYSEC-2026-2020"],"published":"2026-01-28T16:14:28Z","modified":"2026-07-17T16:30:32.009053490Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-qh4c-xf7m-gxfc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24779"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/32746"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/f46d576c54fb8aeec5fc70560e850bed38ef17d7"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24779.json"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2020.yaml"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qh4c-xf7m-gxfc"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2433624"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-24779"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3782"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3462"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3461"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:30089"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:30088"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-rwxx-mrjm-wc2m","slug":"ghsa-rwxx-mrjm-wc2m-e234c364","dossier":false,"summary":"vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends","aliases":["CVE-2026-55574","PYSEC-2026-2304"],"sourceIds":["GHSA-rwxx-mrjm-wc2m","PYSEC-2026-2304"],"published":"2026-07-06T21:16:57.347Z","modified":"2026-07-17T17:15:51.409816079Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-rwxx-mrjm-wc2m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55574"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/pull/45118"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/2b3006076c5e9bc4cda9e03e3641388de3c5c286"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2304.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-rxc4-3w6r-4v47","slug":"ghsa-rxc4-3w6r-4v47-0c8c9269","dossier":false,"summary":"vllm API endpoints vulnerable to Denial of Service Attacks","aliases":["CVE-2025-48956","PYSEC-2026-2021"],"sourceIds":["GHSA-rxc4-3w6r-4v47","PYSEC-2026-2021"],"published":"2025-08-21T14:24:16Z","modified":"2026-07-17T16:30:30.538696375Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-rxc4-3w6r-4v47"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48956"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/23267"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/d8b736f913a59117803d6701521d2e4861701944"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rxc4-3w6r-4v47"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2021.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-vrq3-r879-7m65","slug":"ghsa-vrq3-r879-7m65-0fc59d0f","dossier":false,"summary":"vLLM Tool Schema allows DoS via Malformed pattern and type Fields","aliases":["CVE-2025-48944","PYSEC-2026-2023"],"sourceIds":["GHSA-vrq3-r879-7m65","PYSEC-2026-2023"],"published":"2025-05-28T19:42:32Z","modified":"2026-07-17T16:30:29.005158547Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-vrq3-r879-7m65"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48944"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/17623"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vrq3-r879-7m65"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2023.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-w6q7-j642-7c25","slug":"ghsa-w6q7-j642-7c25-391074f5","dossier":false,"summary":"vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`","aliases":["CVE-2025-48887","PYSEC-2025-50"],"sourceIds":["GHSA-w6q7-j642-7c25","PYSEC-2025-50"],"published":"2025-05-28T17:49:33Z","modified":"2026-06-10T17:14:19.371824623Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-w6q7-j642-7c25"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48887"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/pull/18454"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/4fc1bf813ad80172c1db31264beaef7d93fe0601"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-50.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w6q7-j642-7c25"}],"versionKeys":["pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-wr9h-g72x-mwhm","slug":"ghsa-wr9h-g72x-mwhm-9f241db1","dossier":false,"summary":"vLLM is vulnerable to timing attack at bearer auth","aliases":["CVE-2025-59425","PYSEC-2026-2026"],"sourceIds":["GHSA-wr9h-g72x-mwhm","PYSEC-2026-2026"],"published":"2025-10-07T17:24:47Z","modified":"2026-07-17T16:30:30.606191061Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-wr9h-g72x-mwhm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59425"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/commit/ee10d7e6ff5875386c7f136ce8b5f525c8fcef48"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wr9h-g72x-mwhm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2026.yaml"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/blob/4b946d693e0af15740e9ca9c0e059d5f333b1083/vllm/entrypoints/openai/api_server.py#L1270-L1274"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.0"},{"type":"PACKAGE","url":"https://pypi.org/project/vllm"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-x368-4g9h-fvv4","slug":"ghsa-x368-4g9h-fvv4-37873c2f","dossier":false,"summary":"vLLM makes Use of Uninitialized Resource","aliases":["CVE-2026-7141","PYSEC-2026-2306"],"sourceIds":["GHSA-x368-4g9h-fvv4","PYSEC-2026-2306"],"published":"2026-04-27T17:16:45.637Z","modified":"2026-07-13T16:45:11.279169812Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-7141"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/issues/39146"},{"type":"REPORT","url":"https://github.com/vllm-project/vllm/issues/39146#issue-4215090365"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/pull/39283"},{"type":"FIX","url":"https://github.com/AjAnubolu/vllm/commit/1ad67864c0c20f167929e64c875f5c28e1aad9fd"},{"type":"ADVISORY","url":"https://vuldb.com/submit/801297"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/359740"},{"type":"REPORT","url":"https://vuldb.com/vuln/359740/cti"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-x368-4g9h-fvv4"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2026-227","slug":"pysec-2026-227-5f5a1d28","dossier":false,"summary":null,"aliases":["CVE-2026-54232","GHSA-jrf6-vqxq-pjv2"],"sourceIds":["PYSEC-2026-227"],"published":"2026-06-22T23:16:30.873Z","modified":"2026-06-26T00:00:06.054142968Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"EVIDENCE","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-jrf6-vqxq-pjv2"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3},{"id":"PYSEC-2026-2302","slug":"pysec-2026-2302-60c0b148","dossier":false,"summary":null,"aliases":["CVE-2026-5497"],"sourceIds":["PYSEC-2026-2302"],"published":"2026-06-11T10:16:21.903Z","modified":"2026-07-13T07:15:46.584903724Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-5497"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5497.json"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2487813"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/58ee61422169ce17e08248f8efa1e9df434fe395"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/7bd92629-b396-4449-8f88-6c0092530eb4"}],"versionKeys":["pypi:vllm@0.10.1.1","pypi:vllm@0.11.0","pypi:vllm@0.8.5.post1"],"packageCount":1,"repositoryCount":3}]}}
