GHSA-mcmc-2m55-j8jj: vLLM introduced enhanced protection for CVE-2025-62164
(updated )
The fix here for CVE-2025-62164 is not sufficient. The fix only disables prompt embeds by default rather than addressing the root cause, so the DoS vulnerability remains when the feature is enabled.
References
- access.redhat.com/security/cve/CVE-2026-56340
- bugzilla.redhat.com/show_bug.cgi?id=2491060
- github.com/advisories/GHSA-mcmc-2m55-j8jj
- github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-250.yaml
- github.com/vllm-project/vllm/pull/30649
- github.com/vllm-project/vllm/security/advisories/GHSA-mcmc-2m55-j8jj
- nvd.nist.gov/vuln/detail/CVE-2026-56340
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56340.json
- www.vulncheck.com/advisories/vllm-denial-of-service-via-unvalidated-multimodal-embeddings
Code Behaviors & Features
Detect and mitigate GHSA-mcmc-2m55-j8jj with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →