Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vfm7-4h43-gp6m

Опубликовано: 20 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compatible serving chat endpoint — are susceptible to catastrophic backtracking. An attacker submitting crafted input with nested or repeated structures can trigger severe CPU consumption and performance degradation, resulting in denial of service.

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compatible serving chat endpoint — are susceptible to catastrophic backtracking. An attacker submitting crafted input with nested or repeated structures can trigger severe CPU consumption and performance degradation, resulting in denial of service.

EPSS

Процентиль: 25%
0.00321
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 4.3
redhat
около 2 месяцев назад

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compatible serving chat endpoint — are susceptible to catastrophic backtracking. An attacker submitting crafted input with nested or repeated structures can trigger severe CPU consumption and performance degradation, resulting in denial of service.

CVSS3: 4.3
nvd
около 2 месяцев назад

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compatible serving chat endpoint — are susceptible to catastrophic backtracking. An attacker submitting crafted input with nested or repeated structures can trigger severe CPU consumption and performance degradation, resulting in denial of service.

CVSS3: 4.3
debian
около 2 месяцев назад

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression ...

EPSS

Процентиль: 25%
0.00321
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-1333