/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-w5hw-6gfj-p3hp

Published

Last updated

https://images.chainguard.dev/security/CGA-w5hw-6gfj-p3hp
Package

py3.10-vllm-cuda-11.8

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2025-30165
  • GHSA-9pcc-gvx5-r5wm

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-30165

Updates

Status

Fix not planned

Impact

This issue only affects the V0 engine, which has been off by default since v0.8.0. Further, the issue only applies to a deployment using tensor parallelism across multiple hosts, which upstream does not expect to be a common deployment pattern. Since V0 has been off by default since v0.8.0 and the fix is fairly invasive, Upstream has decided not to fix this issue. Instead recommend that users ensure their environment is on a secure network in case this pattern is in use.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing