pypi:vllmDieses Dossier verknüpft die stabile Identität pypi:vllm mit 3 exakt beobachteten Versionen in 3 öffentlichen Repositories.
Eine Paketidentität oder Provider-Schnittstelle im veröffentlichten Code belegt weder Konfiguration, Konto, Beschaffung, Datentransfer noch API-Aufruf.
Ökosystem:Name + exakte Version + EvidenzpfadVeröffentlichungsalter und Lizenzen stammen aus deps.dev-Metadaten. Sie sind Kontext – kein Wartungs-, Rechts- oder Portabilitätsurteil.
03. Mai 202521. Aug. 202504. Okt. 2025uba-ki-lab/coding-agent-usage-simulationuv.lockuba-ki-lab/llm-questionnaire-benchmarking-frameworkuv.lockuba-ki-lab/llm-testframeworkuv.lockvLLM affected by RCE via auto_map dynamic module loading during model initialization
10. Sept. 2026vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
10. Sept. 2026vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server
10. Sept. 2026vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
10. Sept. 2026vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
10. Sept. 2026vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
10. Sept. 2026Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
07. Aug. 2026vLLM has RCE In Video Processing
10. Sept. 2026vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
10. Sept. 2026vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`
10. Sept. 2026vLLM: Processing differential in multi-channel audio downmixing enables hidden-input/moderation bypass for audio models
17. Juli 2026vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
10. Sept. 2026vLLM: OOM Denial of Service via Audio Decompression Bomb
10. Sept. 2026vLLM DOS: Remotely kill vllm over http with invalid JSON schema
07. Aug. 2026vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out
10. Sept. 2026vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels
10. Sept. 2026vLLM: Cross-User Data Leak Vulnerability
10. Sept. 2026vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
10. Sept. 2026vLLM vulnerable to remote code execution via transformers_utils/get_config
17. Juli 2026vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
10. Sept. 2026vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
17. Sept. 2026vLLM: OpenAI auth bypass
10. Sept. 2026vllm has Improper Resource Shutdown or Release
13. Juli 2026vLLM allows clients to crash the openai server with invalid regex
07. Aug. 2026Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
07. Aug. 2026vLLM has a Weakness in MultiModalHasher Image Hashing Implementation
07. Aug. 2026vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions
10. Sept. 2026vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
17. Sept. 2026vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
10. Sept. 2026vLLM Vulnerable to Remote DoS via Special-Token Placeholders
10. Sept. 2026vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
10. Sept. 2026vLLM vulnerable to Regular Expression Denial of Service
07. Aug. 2026vLLM introduced enhanced protection for CVE-2025-62164
11. Sept. 2026vLLM deserialization vulnerability leading to DoS and potential RCE
10. Sept. 2026vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
10. Sept. 2026vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing
10. Sept. 2026vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
10. Sept. 2026vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector
10. Sept. 2026vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
10. Sept. 2026vllm API endpoints vulnerable to Denial of Service Attacks
10. Sept. 2026vLLM Tool Schema allows DoS via Malformed pattern and type Fields
07. Aug. 2026vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`
07. Aug. 2026vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method
19. Aug. 2026vLLM is vulnerable to timing attack at bearer auth
10. Sept. 2026vLLM makes Use of Uninitialized Resource
10. Sept. 2026Nicht gemeldet
26. Juni 2026Nicht gemeldet
17. Sept. 2026Nicht gemeldet
29. Sept. 2026Nur exakte npm- und PyPI-Tupel werden angereichert. Gemeldete SPDX-Ausdrücke sind Metadaten; daraus folgt keine Bewertung zu Kompatibilität, Pflichten oder Rechtslage.
Abruf, Parsing, Zuordnung und Veröffentlichung verwenden kein generatives KI-Modell.i6eal (2026): vLLM – exaktes KI-Abhängigkeitsevidenz-Dossier, Datenstand 01. Okt. 2026. https://i6eal.de/tools/ki-abhaengigkeitsatlas/paket/vllm-571f04fc/
Wir bauen quellenbasierte Datenprodukte mit stabilen Identitäten, reproduzierbaren Verknüpfungen und sichtbaren Aussagegrenzen.
Diese Tools passen thematisch dazu.