[UPDATE] [medium] vllm: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in vllm to bypass security measures, cause a Denial-of-Service condition, manipulate data, or disclose confidential information.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to bypass security measures, cause a Denial-of-Service condition, manipulate data, or disclose confidential information.
- Who is affected
- Deployments of vllm are affected.
- Urgency
- Remediation is medium urgency due to the variety of potential impacts.
- Action
- Update to the latest version of vllm.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch vllm
Get an email when a new vllm advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1897
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-542330.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-542350.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-539230.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-542360.93% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 58% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-54970.54% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-54233 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54235 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53923 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54236 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-5497 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumGHSA-6pr9-rp53-2pmc: vLLM: OOM Denial of Service via Audio Decompression Bombghsa
- mediumGHSA-hgg8-fqqc-vfmw: vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic routerghsa
- mediumGHSA-5jv2-g5wq-cmr4: vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-ten…ghsa
- mediumGHSA-7h4p-rffg-7823: vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU ker…ghsa
- highGHSA-wcwg-c5fc-9vrc: vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unboun…ghsa
Recent advisories for vllm
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumGHSA-4hhp-h66f-j5j7: vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` an…ghsa · 2026-09-08
- mediumGHSA-7m6h-x95x-82q5: vLLM: Cross-User Data Leak Vulnerabilityghsa · 2026-09-08
- mediumGHSA-pr7f-p5mw-fc87: vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt partsghsa · 2026-09-04
- mediumGHSA-48jh-3gj7-fg8v: vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile ti…ghsa · 2026-09-04
- mediumGHSA-hwrm-c4cx-rf4j: vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messagesghsa · 2026-09-04
- mediumGHSA-8737-qx52-hjff: vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output…ghsa · 2026-09-04
More from CERT-Bund (BSI) Security Advisories
- high[UPDATE] [hoch] Red Hat Enterprise Linux (postgis, virtuoso-opensource): Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Red Hat Enterprise Linux: Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-11
- high[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellen2026-09-11