/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-4p8m-v4w9-8qf2

Published

Last updated

https://images.chainguard.dev/security/CGA-4p8m-v4w9-8qf2
Package

py3.10-vllm-cuda-11.8

Repository

Chainguard

Latest Update
Fixed
Fixed Version

0.6.4-r0

Aliases
  • CVE-2024-47874
  • GHSA-f96h-pmfr-66vw

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-47874

Updates

Status

Fixed

Fixed version

0.6.4-r0

Status

Pending upstream fix

Impact

The starlette dependency used in the vLLM project is a transitive dependency brought in through FastAPI. Due to FastAPI's reliance on this older version of starlette, an upgrade to mitigate the CVE is not feasible and will require action from upstream maintainers of FastAPI to update their compatibility with newer versions of starlette (≥0.40.0).

Status

Under investigation


Safe Source for Open Source™
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing