CVE-2025-71379Disclosure(vllm / vllm)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compatible serving chat endpoint — are susceptible to catastrophic backtracking. An attacker submitting crafted input with nested or repeated structures can trigger severe CPU consumption and performance degradation, resulting in denial of service.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1333

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vllm

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
vllm

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-20: 3Technical Details · 2026-06-20: 306-20
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-71379 Regular Expression Denial of Service in vLLM Versions 0.6.3 Through 0.9.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-71379

    Post summary

    A Regular Expression Denial of Service vulnerability (CVE-2025-71379) affecting vLLM 0.6.3–0.9.0 has been disclosed, with technical details and a link to a vulnerability report.

    0000058
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-71379 vLLM versions &gt;= 0.6.3 and &lt; 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the … https://www.cve.org/CVERecord?id=CVE-2025-71379 ----- Traducción: CVE-2025-71379 vLL… http://infoflow.cloud`

    Post summary

    This post announces CVE-2025-71379, detailing a regular expression denial‑of‑service vulnerability in vLLM versions 0.6.3 to 0.9.0, with technical specifics but no exploit or patch information.

    0000027
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-71379 vLLM versions &gt;= 0.6.3 and &lt; 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the … https://www.cve.org/CVERecord?id=CVE-2025-71379

    Post summary

    The post announces CVE‑2025‑71379 as a ReDoS vulnerability affecting vLLM versions 0.6.3 through 0.9.0, detailing the impacted regex patterns and source files.

    00000420
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvllmvllm---

Explore more