Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-9540

Опубликовано: 26 мая 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance.

A flaw was found in vllm-project vllm, specifically within its OpenAI-compatible Serving Path. A remote attacker could exploit this vulnerability by manipulating certain processing, leading to a denial of service (DoS). This could make the affected service unavailable to legitimate users. The issue impacts the availability of the vllm service.

Отчет

This Moderate-severity denial of service flaw in the vllm OpenAI-compatible Serving Path, as deployed in Red Hat AI Inference Server, Red Hat OpenShift AI, and Red Hat Enterprise Linux AI, allows a remote attacker to disrupt service availability. The vulnerability specifically impacts the ability of the vllm service to process requests, leading to a temporary outage.

Меры по смягчению последствий

To mitigate this issue, restrict network access to the vllm OpenAI-compatible Serving Path to only trusted clients and networks. Implement firewall rules to limit exposure of the service to the public internet or untrusted internal networks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-gaudi-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-neuron-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2481450vllm: vllm: Remote Denial of Service vulnerability in OpenAI-compatible Serving Path

EPSS

Процентиль: 35%
0.00427
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
2 месяца назад

A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance.

CVSS3: 5.3
debian
2 месяца назад

A vulnerability was identified in vllm-project vllm 0.19.0. This issue ...

CVSS3: 5.3
github
2 месяца назад

vllm has Improper Resource Shutdown or Release

EPSS

Процентиль: 35%
0.00427
Низкий

5.3 Medium

CVSS3