/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2025-48956

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-48956

Severity

7.5

High

CVSS V3

Summary

vLLM API endpoints vulnerable to Denial of Service Attacks

Description

vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.10.1.1, a Denial of Service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large header to an HTTP endpoint. This results in server memory exhaustion, potentially leading to a crash or unresponsiveness. The attack does not require authentication, making it exploitable by any remote user. This vulnerability is fixed in 0.10.1.1.

References

Affected packages


Safe Source for Open Source™
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing