Denial of Service Vulnerability in vLLM's Inference Engine
CVE-2025-48943
6.5MEDIUM
What is CVE-2025-48943?
The vLLM inference and serving engine for large language models has a vulnerability that allows for Denial of Service (ReDoS) under specific conditions. When an invalid regular expression is provided while utilizing structured output, the vLLM server may crash, disrupting operations. This issue is present in versions from 0.8.0 up to, but not including, 0.9.0. Users are advised to update to the latest version to ensure protection against this vulnerability.
Affected Version(s)
vllm >= 0.8.0, < 0.9.0