GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
32 advisories
Filter by severity
vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core
Moderate
CVE-2026-105753
was published
for
vllm
(pip)
Oct 6, 2026
vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle
Low
CVE-2026-105752
was published
for
vllm
(pip)
Oct 6, 2026
vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach
Moderate
CVE-2026-105758
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion
Moderate
CVE-2026-105760
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features
Moderate
CVE-2026-105754
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service (3 sites)
Moderate
CVE-2026-105757
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`
Moderate
CVE-2026-105755
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service
Moderate
CVE-2026-105756
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
Moderate
CVE-2026-69147
was published
for
vllm
(pip)
Sep 17, 2026
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
Moderate
CVE-2026-57173
was published
for
vllm
(pip)
Sep 16, 2026
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
Moderate
CVE-2026-73560
was published
for
vllm
(pip)
Sep 8, 2026
vLLM: Cross-User Data Leak Vulnerability
Moderate
CVE-2026-73558
was published
for
vllm
(pip)
Sep 8, 2026
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
Moderate
CVE-2026-73557
was published
for
vllm
(pip)
Sep 4, 2026
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
Moderate
CVE-2026-73556
was published
for
vllm
(pip)
Sep 4, 2026
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
Moderate
CVE-2026-73555
was published
for
vllm
(pip)
Sep 4, 2026
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
Moderate
CVE-2026-71486
was published
for
vllm
(pip)
Sep 4, 2026
vLLM: Completion prompt lists fan out into unbounded engine requests
Moderate
CVE-2026-73559
was published
for
vllm
(pip)
Aug 13, 2026
vLLM denial of service via prompt embeds on M-RoPE models
High
CVE-2026-55514
was published
for
vllm
(pip)
Jul 20, 2026
vLLM: Speech-to-text upload size limit is enforced after full UploadFile read
Moderate
CVE-2026-55646
was published
for
vllm
(pip)
Jul 17, 2026
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
High
CVE-2026-55574
was published
for
vllm
(pip)
Jul 17, 2026
vLLM has Remote DoS via Invalid Recovered Token Reinjection
High
CVE-2026-54234
was published
for
vllm
(pip)
Jul 17, 2026
vLLM: OOM Denial of Service via Audio Decompression Bomb
Moderate
CVE-2026-54233
was published
for
vllm
(pip)
Jun 17, 2026
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
Moderate
CVE-2026-54236
was published
for
vllm
(pip)
Jun 17, 2026
vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
Moderate
CVE-2026-53923
was published
for
vllm
(pip)
Jun 17, 2026
vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
Moderate
CVE-2026-12491
was published
for
vllm
(pip)
Jun 17, 2026
ProTip!
Advisories are also available from the
GraphQL API