CVE-2025-71379
MEDIUMvllm - Regular Expression Denial of Service in Multiple Components
Title source: cnaDescription
vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compatible serving chat endpoint — are susceptible to catastrophic backtracking. An attacker submitting crafted input with nested or repeated structures can trigger severe CPU consumption and performance degradation, resulting in denial of service.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GHSA Advisory GHSA-j828-28rj-hfhp
https://github.com/vllm-project/vllm/security/advisories/GHSA-j828-28rj-hfhp
Third Party Advisory third-party-advisory
VulnCheck Advisory: vllm - Regular Expression Denial of Service in Multiple Components
https://www.vulncheck.com/advisories/vllm-regular-expression-denial-of-service-in-multiple-components
Scores
CVSS v3
4.3
EPSS
0.0032
EPSS Percentile
24.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1333
Status
published
Products (2)
vllm/vllm
0.6.3 - 0.9.0 (2 CPE variants)
vllm/vllm
0.9.0
Published
Jun 20, 2026
Tracked Since
Jun 21, 2026