Impact
An out‑of‑bounds read vulnerability has been identified in vllm-project vLLM. The flaw resides in the conv_ssm_forward function of the mamba_mixer2.py file within the Completions Request Handler. The vulnerability permits an attacker to read memory beyond the intended bounds, potentially exposing sensitive data. The CVSS score of 5.3 indicates a moderate impact, and the exploit type is remote. The description explicitly states that the attack is feasible from a remote context and that the exploit is publicly disclosed.
Affected Systems
vllm‑project vLLM versions up to and including 0.31.0 are affected. Early versions prior to 0.31.0 are not listed as impacted.
Risk and Exploitability
The vulnerability carries a moderate CVSS score of 5.3 but is not currently listed in the CISA KEV catalog. Exploit probability information has not been provided. Because the flaw allows only out‑of‑bounds read, it does not enable arbitrary code execution; however, the remote nature of the attack and lack of mitigation make the vulnerability a usable vector for data leakage until a patch is released.
OpenCVE Enrichment