Логотип exploitDog
bind:CVE-2025-61620
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-61620

Количество 3

Количество 3

redhat логотип

CVE-2025-61620

6 месяцев назад

A flaw was found in the server implementation of vLLM, where the handling of Jinja templates does not properly validate user-supplied input through the chat_template and chat_template_kwargs parameters. When a specially crafted template is processed, it can trigger excessive looping or recursion inside the Jinja engine, consuming large amounts of CPU and memory. This can cause the server to become unresponsive or crash, resulting in a denial-of-service (DoS) condition for applications using vLLM.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-61620

EPSS: Низкий
github логотип

GHSA-6fvq-23cw-5628

6 месяцев назад

vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-61620

A flaw was found in the server implementation of vLLM, where the handling of Jinja templates does not properly validate user-supplied input through the chat_template and chat_template_kwargs parameters. When a specially crafted template is processed, it can trigger excessive looping or recursion inside the Jinja engine, consuming large amounts of CPU and memory. This can cause the server to become unresponsive or crash, resulting in a denial-of-service (DoS) condition for applications using vLLM.

CVSS3: 6.5
6 месяцев назад
debian логотип
-
github логотип
GHSA-6fvq-23cw-5628

vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server

CVSS3: 6.5
6 месяцев назад

Уязвимостей на страницу