CVE-2025-71379: vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Severa
vLLM versions contain multiple ReDoS vulnerabilities, allowing attackers to trigger denial of service.

6 HIGH · 1 INFO · THREAT ORANGE · 7 items · Generated in 412s
vLLM versions contain multiple ReDoS vulnerabilities, allowing attackers to trigger denial of service.
Missing sparse tensor validation in multimodal embeddings processing allows attackers to trigger crashes or resource exhaustion.
LangChain framework has a vulnerability that allows disclosure of files outside the intended boundary when components receive path values from untrusted sources
Arbitrary code execution on the server via a malicious HuggingFace model.
Authenticated users can access unauthorized Ollama backends.
An unauthenticated remote information disclosure vulnerability allows an attacker to read and exfiltrate server's heap memory.
A challenge to hack an AI assistant was run, with 6,000 attempts failing to leak secrets.