CVE-2025-71379

MEDIUM

vllm - Regular Expression Denial of Service in Multiple Components

Title source: cna
STIX 2.1

Description

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compatible serving chat endpoint — are susceptible to catastrophic backtracking. An attacker submitting crafted input with nested or repeated structures can trigger severe CPU consumption and performance degradation, resulting in denial of service.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GHSA Advisory GHSA-j828-28rj-hfhp
https://github.com/vllm-project/vllm/security/advisories/GHSA-j828-28rj-hfhp
Third Party Advisory third-party-advisory
VulnCheck Advisory: vllm - Regular Expression Denial of Service in Multiple Components
https://www.vulncheck.com/advisories/vllm-regular-expression-denial-of-service-in-multiple-components

Scores

CVSS v3 4.3
EPSS 0.0032
EPSS Percentile 24.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1333
Status published
Products (2)
vllm/vllm 0.6.3 - 0.9.0 (2 CPE variants)
vllm/vllm 0.9.0
Published Jun 20, 2026
Tracked Since Jun 21, 2026