V
Üretici güvenlik profili
vllm
Ürün portföyü, yama kanıtları ve sömürü sinyalleri tek güvenlik karnesinde
Veriler CVE Programı, NVD, CISA KEV ve üretici güvenlik bültenlerinden birleştirilir.
Toplam CVE67
Kritik4
CISA KEV0
Public exploit26
Yama oranı%73
Ort. CVSS6.8
12 aylık açık hızı
0
0
2
1
2
4
0
5
4
9
29
11
CVE KEV
CVE önem dağılımı
67toplam CVE
Kritik4 (6%)
Yüksek24 (36%)
Orta37 (55%)
Düşük2 (3%)
Yama ve sömürü görünümü
%73
Doğrulanmış yama
%0
CISA KEV
%39
Public exploit
49Yama var
0Kısmi
0Geçici çözüm
0Üretici: yama yok
18Bilinmiyor
Son güvenlik açıkları
5.3
CVE-2026-105922
vllm-project vLLM Penalty utils.py get_token_bin_counts_and_mask denial of service
V
Yama durumu bilinmiyorEPSS %0
5.3
CVE-2026-105775
vllm-project vLLM Completions Request mamba_mixer2.py conv_ssm_forward out-of-bounds
V
Yama durumu bilinmiyorEPSS %0
5.3
CVE-2026-105760
vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion
V
Yama durumu bilinmiyorEPSS %0
5.9
CVE-2026-105759
vLLM: Unbounded Prometheus label cardinality from attacker-controlled HTTP method tokens in the vLLM Rust frontend metrics middleware (unauthenticated denial of service)
V
Yama durumu bilinmiyorEPSS %0
5.3
CVE-2026-105758
vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach
V
Yama doğrulandıEPSS %0
6.5
CVE-2026-105757
vLLM: Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service (3 sites)
V
Yama doğrulandıEPSS %0
6.5
CVE-2026-105756
vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service
V
Yama doğrulandıEPSS %0
4.2
CVE-2026-105755
vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`
V
Yama doğrulandıEPSS %0
6.5
CVE-2026-105754
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features
V
Yama doğrulandıEPSS %0
6.5
CVE-2026-105753
vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core
V
Yama doğrulandıEPSS %0