PT-2025-18216 · Zeromq+1 · Zeromq+1

Kexinoh

·

Published

2025-03-19

·

Updated

2026-01-11

·

CVE-2025-32444

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vLLM versions 0.6.5 through 0.8.4
Description vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. The issue concerns the use of pickle-based serialization over unsecured ZeroMQ sockets when vLLM is integrated with mooncake, leading to remote code execution. The vulnerable sockets were set to listen on all network interfaces, increasing the likelihood of an attack. vLLM instances without mooncake integration are not vulnerable. This issue has been patched in version 0.8.5.
Recommendations To resolve the issue, update to version 0.8.5 or later. As a temporary workaround, consider disabling the mooncake integration until a patch is applied. Restrict access to the vulnerable ZeroMQ sockets to minimize the risk of exploitation. Avoid using pickle-based serialization over unsecured sockets in the affected API endpoints until the issue is resolved.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-32444
GHSA-HJ4W-HM2G-P6W5
GHSA-X3M8-F7G5-QHM7
PYSEC-2025-42

Affected Products

Zeromq
Vllm