CVE-2025-48942 vLLM DOS: Remotely kill vllm over http with invalid JSON schema

vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, hitting the /v1/completions API with a invalid json_schema as a Guided Param kil ...

Continue Reading
CVE-2025-5358

creation_timestamp| type| source ---|---|--- 2025-05-30 18:17:03+00:00| seen|...Read More ...

Continue Reading
CVE-2022-29469

creation_timestamp| type| source ---|---|--- 2025-05-30 21:02:20+00:00| seen|...Read More ...

Continue Reading
CVE-2025-48883

creation_timestamp| type| source ---|---|--- 2025-05-30 19:07:50+00:00| seen|...Read More ...

Continue Reading
CVE-2025-48885

creation_timestamp| type| source ---|---|--- 2025-05-30 19:07:49+00:00| seen|...Read More ...

Continue Reading
Arrow2 allows out of bounds access in public safe API

Rows::row_unchecked() allows out of bounds access to the underlying buffer without sufficient checks. The arrow2 crate is no longer maintained, so there are no plans to fix this issue. Users are advis ...

Continue Reading
CVE-2025-48949 Navidrome allows SQL Injection via role parameter

Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulnerability due to improper input validation on the role parameter within the API en ...

Continue Reading
CVE-2025-48942 vLLM DOS: Remotely kill vllm over http with invalid JSON schema

vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, hitting the /v1/completions API with a invalid json_schema as a Guided Param kil ...

Continue Reading

Back to Main

Subscribe for the latest news: