Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9hcf-v7m4-6m2j

Опубликовано: 28 мая 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

vLLM allows clients to crash the openai server with invalid regex

Impact

A denial of service bug caused the vLLM server to crash if an invalid regex was provided while using structured output. This vulnerability is similar to GHSA-6qc9-v4r8-22xg, but for regex instead of a JSON schema.

Issue with more details: https://github.com/vllm-project/vllm/issues/17313

Patches

Пакеты

Наименование

vllm

pip
Затронутые версииВерсия исправления

>= 0.8.0, < 0.9.0

0.9.0

EPSS

Процентиль: 14%
0.00046
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-248

Связанные уязвимости

CVSS3: 4.3
redhat
19 дней назад

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) that causes the vLLM server to crash if an invalid regex was provided while using structured output. This vulnerability is similar to GHSA-6qc9-v4r8-22xg/CVE-2025-48942, but for regex instead of a JSON schema. Version 0.9.0 fixes the issue.

CVSS3: 6.5
nvd
19 дней назад

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) that causes the vLLM server to crash if an invalid regex was provided while using structured output. This vulnerability is similar to GHSA-6qc9-v4r8-22xg/CVE-2025-48942, but for regex instead of a JSON schema. Version 0.9.0 fixes the issue.

CVSS3: 6.5
debian
19 дней назад

vLLM is an inference and serving engine for large language models (LLM ...

EPSS

Процентиль: 14%
0.00046
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-248