vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
Published Nov 21, 2025
8.3
HIGHCVSS 4.0
EPSS 0.38%
Description
vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving multimodal models by passing multimodal embedding inputs with correct ndim but incorrect shape (e.g. hidden dimension is wrong), regardless of whether the model is intended to support such inputs (as defined in the Supported Models page). This issue has been patched in version 0.11.1.
Affected products
-
Affected
- ≥ 0.5.5, < 0.11.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Vllm-Project | Vllm | unknown | Affected
|
No data.
Red Hat AI Inference Server 3.2
rhaiis/vllm-cuda-rhel9:1772160593
Fixed · RHSA-2026:3461
Red Hat AI Inference Server 3.2
rhaiis/vllm-cuda-rhel9:3.2.5-1765552580
Fixed · RHSA-2025:23204
Red Hat AI Inference Server 3.2
rhaiis/vllm-rocm-rhel9:1772160625
Fixed · RHSA-2026:3462
Red Hat AI Inference Server 3.2
rhaiis/vllm-rocm-rhel9:3.2.5-1765361180
Fixed · RHSA-2025:23205
Red Hat AI Inference Server 3.2
rhaiis/vllm-rocm-rhel9:3.2.5-1765552603
Fixed · RHSA-2025:23449
Red Hat AI Inference Server 3.2
rhaiis/vllm-tpu-rhel9:3.2.5-1765552619
Fixed · RHSA-2025:23209
Red Hat AI Inference Server
rhaiis/vllm-spyre-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/bootc-amd-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/bootc-aws-nvidia-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/bootc-azure-amd-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/bootc-azure-nvidia-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/bootc-gcp-nvidia-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/bootc-intel-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/bootc-nvidia-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/instructlab-amd-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/instructlab-intel-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/instructlab-nvidia-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-aws-cuda-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-azure-cuda-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gcp-cuda-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-agent-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-controller-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-router-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-storage-initializer-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-vllm-cpu-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-vllm-cuda-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-vllm-gaudi-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-vllm-rocm-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AI Inference Server 3.2 | rhaiis/vllm-cuda-rhel9:1772160593 | Fixed | RHSA-2026:3461 |
| Red Hat AI Inference Server 3.2 | rhaiis/vllm-cuda-rhel9:3.2.5-1765552580 | Fixed | RHSA-2025:23204 |
| Red Hat AI Inference Server 3.2 | rhaiis/vllm-rocm-rhel9:1772160625 | Fixed | RHSA-2026:3462 |
| Red Hat AI Inference Server 3.2 | rhaiis/vllm-rocm-rhel9:3.2.5-1765361180 | Fixed | RHSA-2025:23205 |
| Red Hat AI Inference Server 3.2 | rhaiis/vllm-rocm-rhel9:3.2.5-1765552603 | Fixed | RHSA-2025:23449 |
| Red Hat AI Inference Server 3.2 | rhaiis/vllm-tpu-rhel9:3.2.5-1765552619 | Fixed | RHSA-2025:23209 |
| Red Hat AI Inference Server | rhaiis/vllm-spyre-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/bootc-amd-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/bootc-aws-nvidia-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/bootc-azure-amd-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/bootc-azure-nvidia-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/bootc-gcp-nvidia-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/bootc-intel-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/bootc-nvidia-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/instructlab-amd-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/instructlab-intel-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/instructlab-nvidia-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-aws-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-azure-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gcp-cuda-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-agent-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-controller-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-router-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-storage-initializer-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-vllm-cpu-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-vllm-cuda-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-vllm-gaudi-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-vllm-rocm-rhel9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw is rated Moderate rather than Important because its impact is strictly limited to availability and requires low but existing privileges to exploit. The issue arises from incomplete shape validation of multimodal embedding tensors, which can cause deterministic crashes in the inference engine, but it does not enable memory corruption, data leakage, integrity compromise, or execution of arbitrary code. Exploitation requires an authenticated or API-key-holding user to submit malformed multimodal inputs, meaning it cannot be triggered by an unauthenticated attacker on an exposed endpoint. Additionally, the failure mode is a clean crash rather than undefined behavior, so the blast radius is constrained to service interruption rather than broader systemic compromise. These factors—PR:L requirement, no confidentiality/integrity impact, deterministic failure mode, and scoped DoS only—technically align the issue with Moderate severity instead of an Important flaw.
Red Hat mitigation
No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.
References (13)
- https://access.redhat.com/security/cve/CVE-2025-62372 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2416280 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-198357 Advisory
- https://github.com/advisories/GHSA-pmqf-x6x8-p7qw Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2019.yaml
- https://github.com/vllm-project/vllm
- https://github.com/vllm-project/vllm/commit/58fab50d82838d5014f4a14d991fdb9352c9c84b x_refsource_MISCPatch
- https://github.com/vllm-project/vllm/pull/27204 x_refsource_MISCIssue TrackingPatchVendor Advisory
- https://github.com/vllm-project/vllm/pull/6613 x_refsource_MISCIssue Tracking
- https://github.com/vllm-project/vllm/security/advisories/GHSA-pmqf-x6x8-p7qw x_refsource_CONFIRMMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-62372
- https://pypi.org/project/vllm
- https://www.cve.org/CVERecord?id=CVE-2025-62372
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-62372 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2416280 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-198357 | Advisory | |
| https://github.com/advisories/GHSA-pmqf-x6x8-p7qw | Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2019.yaml | ||
| https://github.com/vllm-project/vllm | ||
| https://github.com/vllm-project/vllm/commit/58fab50d82838d5014f4a14d991fdb9352c9c84b | x_refsource_MISCPatch | |
| https://github.com/vllm-project/vllm/pull/27204 | x_refsource_MISCIssue TrackingPatchVendor Advisory | |
| https://github.com/vllm-project/vllm/pull/6613 | x_refsource_MISCIssue Tracking | |
| https://github.com/vllm-project/vllm/security/advisories/GHSA-pmqf-x6x8-p7qw | x_refsource_CONFIRMMitigationVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-62372 | ||
| https://pypi.org/project/vllm | ||
| https://www.cve.org/CVERecord?id=CVE-2025-62372 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub