Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16353 | vLLM Tool Schema allows DoS via Malformed pattern and type Fields |
Github GHSA |
GHSA-vrq3-r879-7m65 | vLLM Tool Schema allows DoS via Malformed pattern and type Fields |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 01 Jul 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vllm
Vllm vllm |
|
| CPEs | cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vllm
Vllm vllm |
Sat, 31 May 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 30 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 May 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, the vLLM backend used with the /v1/chat/completions OpenAPI endpoint fails to validate unexpected or malformed input in the "pattern" and "type" fields when the tools functionality is invoked. These inputs are not validated before being compiled or parsed, causing a crash of the inference worker with a single request. The worker will remain down until it is restarted. Version 0.9.0 fixes the issue. | |
| Title | vLLM Tool Schema allows DoS via Malformed pattern and type Fields | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-30T18:56:56.406Z
Reserved: 2025-05-28T18:49:07.582Z
Link: CVE-2025-48944
Updated: 2025-05-30T18:56:52.880Z
Status : Analyzed
Published: 2025-05-30T19:15:30.433
Modified: 2025-07-01T20:42:13.840
Link: CVE-2025-48944
OpenCVE Enrichment
Updated: 2025-06-24T09:44:17Z
EUVD
Github GHSA