Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-71379

Опубликовано: 20 июн. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compatible serving chat endpoint — are susceptible to catastrophic backtracking. An attacker submitting crafted input with nested or repeated structures can trigger severe CPU consumption and performance degradation, resulting in denial of service.

A flaw was found in vLLM. Multiple regular expression denial of service (ReDoS) vulnerabilities exist in versions greater than or equal to 0.6.3 and less than 0.9.0. An attacker can exploit this by submitting crafted input with nested or repeated structures to specific regex patterns within vLLM, such as those in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compatible serving chat endpoint. This can lead to severe CPU consumption and performance degradation, resulting in a denial of service (DoS) for the affected system.

Отчет

Red Hat rates this issue as having Low impact for Red Hat AI products. Shipped vLLM versions in Red Hat OpenShift AI, Red Hat AI Inference Server, and Red Hat Enterprise Linux AI do not include the vulnerable regular expression code paths.

Меры по смягчению последствий

No mitigation required for unaffected versions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Not affected
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Not affected
Red Hat AI Inference Serverrhaii/vllm-cuda-rhel9Not affected
Red Hat AI Inference Serverrhaii/vllm-gaudi-rhel9Not affected
Red Hat AI Inference Serverrhaii/vllm-neuron-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2491059vllm: vLLM: Denial of Service via regular expression denial of service (ReDoS) vulnerabilities

EPSS

Процентиль: 24%
0.00321
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 месяцев назад

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compatible serving chat endpoint — are susceptible to catastrophic backtracking. An attacker submitting crafted input with nested or repeated structures can trigger severe CPU consumption and performance degradation, resulting in denial of service.

CVSS3: 4.3
debian
около 2 месяцев назад

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression ...

CVSS3: 4.3
github
около 2 месяцев назад

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compatible serving chat endpoint — are susceptible to catastrophic backtracking. An attacker submitting crafted input with nested or repeated structures can trigger severe CPU consumption and performance degradation, resulting in denial of service.

EPSS

Процентиль: 24%
0.00321
Низкий

4.3 Medium

CVSS3