Back

HIGH

vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs

Published Nov 21, 2025

Description

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving multimodal models by passing multimodal embedding inputs with correct ndim but incorrect shape (e.g. hidden dimension is wrong), regardless of whether the model is intended to support such inputs (as defined in the Supported Models page). This issue has been patched in version 0.11.1.

Affected products

Remediation

Red Hat statement

This flaw is rated Moderate rather than Important because its impact is strictly limited to availability and requires low but existing privileges to exploit. The issue arises from incomplete shape validation of multimodal embedding tensors, which can cause deterministic crashes in the inference engine, but it does not enable memory corruption, data leakage, integrity compromise, or execution of arbitrary code. Exploitation requires an authenticated or API-key-holding user to submit malformed multimodal inputs, meaning it cannot be triggered by an unauthenticated attacker on an exposed endpoint. Additionally, the failure mode is a clean crash rather than undefined behavior, so the blast radius is constrained to service interruption rather than broader systemic compromise. These factors—PR:L requirement, no confidentiality/integrity impact, deterministic failure mode, and scoped DoS only—technically align the issue with Moderate severity instead of an Important flaw.

Red Hat mitigation

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Nov 21, 2025
Updated Nov 24, 2025
Reserved Oct 10, 2025

CISA Vulnrichment

Updated Nov 24, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Nov 21, 2025
Bugzilla 2416280

ENISA EUVD

Assigner GitHub_M
Published Nov 21, 2025
Updated Nov 24, 2025