PT-2025-18217 · Vllm · Vllm

·

CVE-2025-46560

·

Published

2025-04-29

·

Updated

2026-07-07

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions vLLM versions 0.8.0 through 0.8.4
Description The issue concerns a critical performance vulnerability in the input preprocessing logic of the multimodal tokenizer. It is caused by inefficient list concatenation operations, resulting in quadratic time complexity (O(n²)), which allows malicious actors to trigger resource exhaustion via specially crafted inputs.
Recommendations For versions 0.8.0 through 0.8.4, update to version 0.8.5 to resolve the issue. As a temporary workaround, consider restricting the use of the multimodal tokenizer to minimize the risk of exploitation.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03424
CVE-2025-46560
GHSA-VC6M-HM49-G9QG
PYSEC-2026-2022

Affected Products

Vllm