Security Flaw in vLLM Inference Engine by vLLM Project
CVE-2025-47277
What is CVE-2025-47277?
The vLLM inference engine can expose a security risk when using the PyNcclPipe KV cache transfer integration, particularly in versions 0.6.5 through 0.8.4. This vulnerability allows the TCPStore interface to listen on all network interfaces instead of being restricted to a private network as intended, potentially enabling unauthorized access. The issue arises when the --kv-ip parameter, meant for private communication, is misconfigured. A patch in version 0.8.5 resolves this by ensuring the TCPStore binds to a specified private interface, thereby enhancing security against unwanted access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
vllm >= 0.6.5, < 0.8.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
