PT-2025-18217 · Vllm · Vllm

D3Do-23

+2

·

Published

2025-04-29

·

Updated

2025-04-30

·

CVE-2025-46560

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions vLLM versions 0.8.0 through 0.8.4
Description The issue concerns a critical performance vulnerability in the input preprocessing logic of the multimodal tokenizer. It is caused by inefficient list concatenation operations, resulting in quadratic time complexity (O(n²)), which allows malicious actors to trigger resource exhaustion via specially crafted inputs.
Recommendations For versions 0.8.0 through 0.8.4, update to version 0.8.5 to resolve the issue. As a temporary workaround, consider restricting the use of the multimodal tokenizer to minimize the risk of exploitation.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

BDU:2026-03424
CVE-2025-46560
GHSA-VC6M-HM49-G9QG

Affected Products

Vllm