216.73.217.22

CVE-2025-62372

· Published 21/11/2025 02:15 · Modified 04/12/2025 17:40

Labels: CVE-2025-62372 2025-11-21CVE-2025-62372CWE-129[email protected]

Essential information

Published
21/11/2025 02:15
Modified
04/12/2025 17:40
Author
Creator
CVSS
8.3 HIGH (v3) 8.3 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving multimodal models by passing multimodal embedding inputs with correct ndim but incorrect shape (e.g. hidden dimension is wrong), regardless of whether the model is intended to support such inputs (as defined in the Supported Models page). This issue has been patched in version 0.11.1.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
vllm / vllm cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*
vllm / vllm cpe:2.3:a:vllm:vllm:0.11.1:rc0:*:*:*:*:*:*
vllm / vllm cpe:2.3:a:vllm:vllm:0.11.1:rc1:*:*:*:*:*:*

References