Логотип exploitDog
bind:CVE-2025-62372
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-62372

Количество 5

Количество 5

redhat логотип

CVE-2025-62372

5 месяцев назад

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving multimodal models by passing multimodal embedding inputs with correct ndim but incorrect shape (e.g. hidden dimension is wrong), regardless of whether the model is intended to support such inputs (as defined in the Supported Models page). This issue has been patched in version 0.11.1.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-62372

5 месяцев назад

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving multimodal models by passing multimodal embedding inputs with correct ndim but incorrect shape (e.g. hidden dimension is wrong), regardless of whether the model is intended to support such inputs (as defined in the Supported Models page). This issue has been patched in version 0.11.1.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-62372

5 месяцев назад

vLLM is an inference and serving engine for large language models (LLM ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-pmqf-x6x8-p7qw

5 месяцев назад

vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2025-14667

5 месяцев назад

Уязвимость библиотеки для работы с большими языковыми моделями (LLM) vLLM, связанная с непроверенным индексированием массива, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-62372

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving multimodal models by passing multimodal embedding inputs with correct ndim but incorrect shape (e.g. hidden dimension is wrong), regardless of whether the model is intended to support such inputs (as defined in the Supported Models page). This issue has been patched in version 0.11.1.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-62372

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving multimodal models by passing multimodal embedding inputs with correct ndim but incorrect shape (e.g. hidden dimension is wrong), regardless of whether the model is intended to support such inputs (as defined in the Supported Models page). This issue has been patched in version 0.11.1.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-62372

vLLM is an inference and serving engine for large language models (LLM ...

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-pmqf-x6x8-p7qw

vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs

CVSS3: 6.5
0%
Низкий
5 месяцев назад
fstec логотип
BDU:2025-14667

Уязвимость библиотеки для работы с большими языковыми моделями (LLM) vLLM, связанная с непроверенным индексированием массива, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.7
0%
Низкий
5 месяцев назад

Уязвимостей на страницу