vllm-cu129

Direct Vulnerabilities

Known vulnerabilities in the vllm-cu129 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Improper Certificate Validation

<0.23.0-r0
  • L
Resource Exhaustion

<0.23.0-r0
  • L
HTTP Request Smuggling

<0.25.1-r1
  • L
Out-of-bounds Read

<0.25.1-r1
  • L
Improper Input Validation

<0.25.1-r1
  • L
Resource Exhaustion

<0.25.0-r0
  • L
Resource Exhaustion

<0.25.0-r0
  • L
Resource Exhaustion

<0.25.0-r0
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0.25.0-r0
  • L
Uncontrolled Memory Allocation

<0.25.0-r0
  • H
Allocation of Resources Without Limits or Throttling

<0.25.0-r0
  • L
Out-of-bounds Read

<0.25.0-r0
  • L
OS Command Injection

<0.25.0-r0
  • L
Resource Exhaustion

<0.25.0-r0
  • L
Integer Overflow or Wraparound

<0.25.0-r0
  • L
Uncontrolled Memory Allocation

<0.25.0-r0
  • L
Uncontrolled Memory Allocation

<0.25.0-r0
  • L
Uncontrolled Memory Allocation

<0.25.0-r0
  • L
Integer Overflow or Wraparound

<0.25.0-r0
  • C
Out-of-bounds Read

<0.25.0-r0
  • L
Out-of-bounds Write

<0.25.0-r0
  • L
Missing Authorization

<0.22.0-r0
  • L
Authorization Bypass Through User-Controlled Key

<0.22.0-r0
  • L
Origin Validation Error

<0.24.0-r0
  • L
Use of a Broken or Risky Cryptographic Algorithm

<0.23.0-r0
  • L
CVE-2026-55514

<0.24.0-r0
  • L
Improper Input Validation

<0.24.0-r0
  • L
Resource Exhaustion

<0.24.0-r0
  • L
CVE-2026-55574

<0.24.0-r0
  • M
Misinterpretation of Input

<0.24.0-r0
  • L
Improper Handling of Highly Compressed Data (Data Amplification)

<0.24.0-r0
  • L
Information Exposure

<0.24.0-r0
  • L
GHSA-4xgf-cpjx-pc3j

<0.24.0-r0
  • L
Information Exposure Through Log Files

<0.24.0-r0
  • L
Improper Validation of Specified Type of Input

<0.24.0-r0
  • L
Uncontrolled Search Path Element

<0.22.1-r0
  • L
HTTP Request Smuggling

<0.22.0-r0
  • L
Arbitrary Code Injection

<0.22.0-r0
  • L
CRLF Injection

<0.22.1-r0
  • L
Improper Authentication

<0.21.0-r3
  • L
Improper Restriction of Rendered UI Layers or Frames

<0.25.1-r1
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<0.21.0-r3
  • L
Improper Cleanup on Thrown Exception

<0.21.0-r3
  • L
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

<0.22.0-r0
  • L
CVE-2026-48818

<0.22.0-r0
  • L
Allocation of Resources Without Limits or Throttling

<0.23.0-r0
  • L
GHSA-537c-gmf6-5ccf

<0.23.0-r0
  • L
CVE-2026-27145

*
  • L
Interpretation Conflict

<0.22.1-r0
  • L
Improper Handling of Highly Compressed Data (Data Amplification)

<0.23.0-r0
  • L
Resource Exhaustion

<0.22.1-r0
  • L
Improper Restriction of Rendered UI Layers or Frames

<0.25.1-r1
  • L
Resource Exhaustion

<0.25.1-r1
  • L
CVE-2026-42507

*
  • L
Improper Validation of Certificate with Host Mismatch

<0.23.0-r0
  • L
Improper Verification of Cryptographic Signature

<0.21.0-r3
  • L
Improper Validation of Specified Quantity in Input

<0.22.1-r0
  • L
Use of Incorrectly-Resolved Name or Reference

<0.23.0-r0
  • L
Allocation of Resources Without Limits or Throttling

<0.23.0-r0
  • L
Improper Resource Shutdown or Release

<0.23.0-r0
  • L
Information Exposure

<0.23.0-r0
  • L
Resource Exhaustion

<0.21.0-r3
  • L
Allocation of Resources Without Limits or Throttling

<0.23.0-r0
  • L
Allocation of Resources Without Limits or Throttling

<0.23.0-r0
  • L
Improper Input Validation

<0.22.1-r0
  • L
Improper Initialization

<0.23.0-r0
  • L
Improper Restriction of Rendered UI Layers or Frames

<0.25.1-r1
  • L
Insufficient Verification of Data Authenticity

<0.22.0-r0
  • L
CVE-2026-39821

<0.25.1-r1
  • H
Double Free

<0.25.1-r1
  • L
Cross-site Scripting (XSS)

<0.25.1-r1
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0.25.1-r1
  • L
CVE-2026-42499

<0.25.1-r1
  • H
Allocation of Resources Without Limits or Throttling

<0.25.1-r1
  • H
Deserialization of Untrusted Data

<0.22.1-r0
  • H
Origin Validation Error

<0.22.1-r0
  • M
HTTP Request Smuggling

<0.22.0-r0
  • M
Inefficient Regular Expression Complexity

<0.21.0-r0
  • M
Information Exposure

<0.20.2-r0
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<0.20.2-r0
  • L
CVE-2025-69872

<0.26.0-r0