CVE-2025-48956

HIGH

vLLM <0.10.1.1 - DoS

Title source: llm
STIX 2.1

Description

vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.10.1.1, a Denial of Service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large header to an HTTP endpoint. This results in server memory exhaustion, potentially leading to a crash or unresponsiveness. The attack does not require authentication, making it exploitable by any remote user. This vulnerability is fixed in 0.10.1.1.

Scores

CVSS v3 7.5
EPSS 0.0031
EPSS Percentile 53.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (2)
pypi/vllm 0.1.0 - 0.10.1.1PyPI
vllm/vllm 0.1.0 - 0.10.1.1
Published Aug 21, 2025
Tracked Since Feb 18, 2026