Bounties
Partners
Community
Info
vllm-project / vllm
Project repository
A high-throughput and memory-efficient inference and serving engine for LLMs
Submit a report
FIRST INTERACTION
WITHIN
9 DAYS
REVIEW
WITHIN
14 DAYS
FIX
WITHIN
N/A DAYS
chat_template_kwargs Injection Bypasses trust_request_chat_template Guard
Apr 25th 2026
jd-admrl-ai
•
self closed
SSRF Amplification via aiohttp trust_env=True Bypasses allowed_media_domains All...
Apr 25th 2026
jd-admrl-ai
•
self closed
Path Traversal via Unsanitized lora_path in /v1/load_lora_adapter Endpoint
Apr 25th 2026
jd-admrl-ai
•
self closed
SSRF via Unrestricted Multimodal URL Fetching - allowed_media_domains Check Bypa...
Apr 25th 2026
jd-admrl-ai
•
self closed
Arbitrary file clobber via checkpoint state-dict keys when loading untrusted mod...
Apr 20th 2026
mirr2
•
self closed
Responses API trust-boundary collapse via caller-controlled request_id enables c...
Apr 20th 2026
mirr2
•
self closed
SSRF via allowlisted-domain redirect laundering in batch media fetch path
Apr 20th 2026
mirr2
•
self closed
Server-Side Request Forgery (SSRF) via Multimodal Media URL Fetching — Cloud Cre...
Apr 13th 2026
skillwager
•
duplicate
None
Authentication Bypass and Arbitrary Method Execution via Dev Mode Endpoints
Apr 11th 2026
skillwager
•
duplicate
None
SSRF via multimodal image/audio/video URL fetching in chat completions API — no...
Apr 13th 2026
snakeyworm
•
duplicate
High
SSRF via Multimodal Media URL Fetch in Chat Completions API
Apr 13th 2026
skillwager
•
not applicable
Auth Bypass + Arbitrary Method Execution via Dev Mode Endpoints (/collective_rpc...
Apr 13th 2026
skillwager
•
spam
Unauthenticated SSRF via multimodal image_url field — empty list falsy bypass al...
Apr 13th 2026
radikhoroshev
•
duplicate
High
Authentication bypass on 6+ endpoints — auth middleware only protects /v1 paths,...
Apr 13th 2026
snakeyworm
•
not applicable
Authentication bypass on 6+ endpoints — auth middleware only protects /v1 paths,...
Apr 13th 2026
snakeyworm
•
not applicable
Arbitrary code execution via unsafe torch.load() without weights_only in 4 core...
Apr 13th 2026
elliottower
•
not applicable
SSRF via multimodal image/audio/video URLs — no domain restriction in default co...
Apr 13th 2026
microwaveovens-yay
•
duplicate
Medium
Authentication middleware only protects /v1 endpoints — /sleep, /wake_up, /start...
Apr 11th 2026
microwaveovens-yay
•
duplicate
High
OOM Denial of Service via Audio Decompression Bomb
Apr 13th 2026
rtv-git
•
not applicable
GPU Memory Read/Write via Unauthenticated NIXL Handshake Metadata Disclosure
Apr 5th 2026
rtv-git
•
self closed
GPU DMA Channel Hijacking via Unauthenticated NCCL unique_id Injection in P2pNcc...
Apr 5th 2026
rtv-git
•
self closed
API routes without /v1 prefix bypass API-key authentication in vLLM server
Apr 13th 2026
9to5ai
•
not applicable
Unauthenticated Memory Exhaustion DoS via Unbounded Audio Queue in WebSocket /v1...
Apr 13th 2026
xandramax
•
not applicable
Security Check Bypass via assert Statement in Activation Function Loading
Apr 13th 2026
pierreolivierbonin
•
not applicable
API Key Authentication Bypass on Non-/v1 Endpoints (SageMaker, tokenize, etc.)
Apr 13th 2026
lihfdgjr
•
not applicable
SSRF via Multimodal Media URL Fetching in vLLM
Apr 2nd 2026
pierreolivierbonin
•
self closed
Automated Safety Guardrail Bypass in Llama-3.1-8b-Instruct (Malware Generation)
Mar 30th 2026
s05161497-sudo
•
not applicable
Unauthenticated Denial of Service via Elastic Endpoint Scaling API
Mar 29th 2026
hacnho
•
duplicate
High
Unauthenticated Arbitrary Worker Method Execution via collective_rpc API
Mar 30th 2026
hacnho
•
not applicable
Path Traversal via Malicious Weight Names in np_cache Loading
Apr 13th 2026
hacnho
•
not applicable
SSRF via Multimodal Media URLs + Authentication Bypass on Non-/v1 Endpoints
Apr 13th 2026
hacnho
•
duplicate
High
WebSocket KeyError in AuthenticationMiddleware breaks `/v1/realtime` when API ke...
Mar 27th 2026
vitocrl
•
not applicable
Unauthenticated server-wide DoS via `/scale_elastic_ep` auth bypass
Mar 26th 2026
vitocrl
•
duplicate
High
Authentication Bypass on Non-/v1 Endpoints Enables Unauthenticated Inference and...
Mar 27th 2026
0xbassia
•
not applicable
RCE via ungated cloudpickle.loads() in run_method() bypasses VLLM_ALLOW_INSECURE...
Mar 30th 2026
nhomyk
•
not applicable
Denial of Service via Multiple Logic Bugs in Realtime API WebSocket Handler
Apr 13th 2026
seory0
•
not applicable
SSRF in Batch API download_bytes_from_url allows fetching internal services and...
Apr 13th 2026
narrator3333-hash
•
not applicable
SSRF + Local File Read via Multimodal Media URL — Default Domain Whitelist Bypas...
Apr 13th 2026
appsecguardian-hash
•
duplicate
High
Pre-Auth RCE via Unauthenticated Pickle Deserialization in Distributed Communic...
Mar 27th 2026
appsecguardian-hash
•
not applicable
Unsafe deserialization via torch.load and pickle in vLLM model loading
Mar 27th 2026
etwithin
•
spam
LoRA Adapter rank=0 ZeroDivisionError DoS in PEFTHelper — Validation Bypass via...
Mar 8th 2026
apeiria-zero
•
self closed
Server-Side Request Forgery (SSRF) in vLLM Multimodal Media Connector Due to Emp...
Apr 13th 2026
invisiblemonsters
•
duplicate
High
Server-Side Request Forgery via Default Media URL Configuration — No Private IP...
Apr 13th 2026
apeiria-zero
•
duplicate
High
vLLM Unsafe Pickle Deserialization in /update_weights Endpoint — Unauthenticated...
Mar 27th 2026
avienma007
•
not applicable
vLLM Server-Side Request Forgery via Media URL Fetching
Apr 13th 2026
rezaduty
•
duplicate
Critical
Authentication Bypass via /invocations Endpoint in vLLM — Unauthorized Model Inf...
Feb 22nd 2026
nottiboy137
•
duplicate
Critical
Authentication Bypass for Non-/v1 Endpoints Exposes Tokenization and Server Conf...
Feb 22nd 2026
shima-coder
•
duplicate
Medium
SSRF via Multimodal Media URL Fetching Allows Cloud Metadata Theft and Internal...
Apr 13th 2026
shima-coder
•
duplicate
High
SSRF via Unrestricted Multimodal Media URL Fetching (Default Empty allowed_media...
Apr 13th 2026
invisiblemonsters
•
not applicable
NaN/Infinity Validation Bypass in SamplingParams via OpenAI-Compatible API
Feb 13th 2026
drrose2029
•
not applicable
Denial of Service via Unauthenticated /scale_elastic_ep Endpoint Setting Global...
Feb 13th 2026
seory0
•
not applicable
Authentication Bypass via Path Prefix Check in AuthenticationMiddleware Allowing...
Feb 13th 2026
seory0
•
not applicable
Path Traversal in LoRA Adapter Loading API Allows File Existence Oracle
Mar 26th 2026
222n5
•
not applicable
Remote Code Execution (RCE) via auto_map Dynamic Module Loading bypassing trust_...
Jan 30th 2026
amadhan882
•
not applicable
Remote Code Execution via Insecure Deserialization (pickle.loads/cloudpickle.loa...
Jan 22nd 2026
sermikr0
•
spam
Unhandled Memory Corruption Resulting in DDOS
Mar 8th 2026
kattraxler
•
pending
Remote code execution via transformers_utils/get_config
Feb 8th 2026
vancir
•
High
High
•
CVE-2026-4943
CVE-2026-4943
Remote code execution may occur through the calculate_expression tool helper in...
Oct 23rd 2025
dev-mhyun
•
not applicable
Undocumented Automatic Fallback to Unsafe Model Loading Creates Silent RCE Risk
Oct 14th 2025
rudra2018
•
informative
High
vLLM Server Unsafe Deserialization Leads to Arbitrary Code Execution
Mar 22nd 2025
racerz-fighting
•
not applicable
Remote Code Execution in Insecure Pickle Deserialization via recv_obj() in class...
Feb 20th 2025
seaw1nd
•
duplicate
Critical
vLLM Server Unsafe Deserialization Leads to Arbitrary Code Execution
Feb 1st 2025
avilum
•
informative
Critical
Remote Code Execution by Pickle Deserialization via MessageQueue.dequeue() Broad...
Dec 30th 2024
zpbrent
•
Critical
•
$1500
Critical
•
$1500
•
CVE-2024-11041
CVE-2024-11041
"POST /v1/completions" and "POST /v1/embeddings" Denials of Service
Dec 16th 2024
rh-tguittet
•
High
•
$750
High
•
$750
•
CVE-2024-11040
CVE-2024-11040
vllm has Cloudpickle deserializes arbitrary command execution
Dec 7th 2024
hexian2001
•
duplicate
Critical
Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC s...
Dec 6th 2024
zpbrent
•
Critical
•
$1500
Critical
•
$1500
•
CVE-2024-9053
CVE-2024-9053
Remote Code Execution by Pickle Deserialization via recv_object() distributed tr...
Dec 6th 2024
zpbrent
•
Critical
•
$1500
Critical
•
$1500
•
CVE-2024-9052
CVE-2024-9052
Command Injection in nccl_integrity_check function
Jun 12th 2024
vanirxxx
•
informative
High
Malicious model to RCE by torch.load in hf_model_weights_iterator (as well as th...
May 28th 2024
dogewatch
•
informative
Critical
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0