/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2025-29783

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-29783

CGA ID

CGA-539g-3mpq-j564

Severity

Unknown

Description

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Mooncake, unsafe deserialization exposed directly over ZMQ/TCP on all network interfaces will allow attackers to execute remote code on distributed hosts. This is a remote code execution vulnerability impacting any deployments using Mooncake to distribute KV across distributed hosts. This vulnerability is fixed in 0.8.0.

References

  • https://images.chainguard.dev/security/CGA-539g-3mpq-j564

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs