CVE-2025-71379: Vllm
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compatible serving chat endpoint — are susceptible to catastrophic backtracking. An attacker submitting crafted input with nested or repeated structures can trigger severe CPU consumption and performance degradation, resulting in denial of service.
Affected products
- Vllm Vllm: from 0.6.3, before 0.9.0 (fixed in 0.9.0)
Published 2026-06-20. Last modified 2026-10-05.