PT-2025-47649 · Vllm · Vllm
Published
2025-11-20
·
Updated
2025-12-04
·
CVE-2025-62372
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H |
Name of the Vulnerable Software and Affected Versions
vLLM versions 0.5.5 through 0.11.0
Description
vLLM is an inference and serving engine for large language models (LLMs). Users can cause the vLLM engine to crash when serving multimodal models by providing multimodal embedding inputs with a correct number of dimensions (ndim) but an incorrect shape, such as a wrong hidden dimension. This occurs regardless of whether the model is designed to handle such inputs.
Recommendations
Update to version 0.11.1 or later.
Exploit
Fix
DoS
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vllm