Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-48943

Опубликовано: 30 мая 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) that causes the vLLM server to crash if an invalid regex was provided while using structured output. This vulnerability is similar to GHSA-6qc9-v4r8-22xg/CVE-2025-48942, but for regex instead of a JSON schema. Version 0.9.0 fixes the issue.

EPSS

Процентиль: 19%
0.0006
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-248

Связанные уязвимости

CVSS3: 4.3
redhat
3 месяца назад

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) that causes the vLLM server to crash if an invalid regex was provided while using structured output. This vulnerability is similar to GHSA-6qc9-v4r8-22xg/CVE-2025-48942, but for regex instead of a JSON schema. Version 0.9.0 fixes the issue.

CVSS3: 6.5
debian
3 месяца назад

vLLM is an inference and serving engine for large language models (LLM ...

CVSS3: 6.5
github
3 месяца назад

vLLM allows clients to crash the openai server with invalid regex

EPSS

Процентиль: 19%
0.0006
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-248