Логотип exploitDog
bind:CVE-2025-48943
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-48943

Количество 4

Количество 4

redhat логотип

CVE-2025-48943

20 дней назад

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) that causes the vLLM server to crash if an invalid regex was provided while using structured output. This vulnerability is similar to GHSA-6qc9-v4r8-22xg/CVE-2025-48942, but for regex instead of a JSON schema. Version 0.9.0 fixes the issue.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-48943

20 дней назад

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) that causes the vLLM server to crash if an invalid regex was provided while using structured output. This vulnerability is similar to GHSA-6qc9-v4r8-22xg/CVE-2025-48942, but for regex instead of a JSON schema. Version 0.9.0 fixes the issue.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-48943

20 дней назад

vLLM is an inference and serving engine for large language models (LLM ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9hcf-v7m4-6m2j

22 дня назад

vLLM allows clients to crash the openai server with invalid regex

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-48943

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) that causes the vLLM server to crash if an invalid regex was provided while using structured output. This vulnerability is similar to GHSA-6qc9-v4r8-22xg/CVE-2025-48942, but for regex instead of a JSON schema. Version 0.9.0 fixes the issue.

CVSS3: 4.3
0%
Низкий
20 дней назад
nvd логотип
CVE-2025-48943

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) that causes the vLLM server to crash if an invalid regex was provided while using structured output. This vulnerability is similar to GHSA-6qc9-v4r8-22xg/CVE-2025-48942, but for regex instead of a JSON schema. Version 0.9.0 fixes the issue.

CVSS3: 6.5
0%
Низкий
20 дней назад
debian логотип
CVE-2025-48943

vLLM is an inference and serving engine for large language models (LLM ...

CVSS3: 6.5
0%
Низкий
20 дней назад
github логотип
GHSA-9hcf-v7m4-6m2j

vLLM allows clients to crash the openai server with invalid regex

CVSS3: 6.5
0%
Низкий
22 дня назад

Уязвимостей на страницу