** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-8939. Notes: All CVE users should reference CVE-2024-8939 instead of this CVE Record. All references and descriptions in this candidate have been removed to prevent accidental usage.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Denial of Service in vllm-project/vllm | vllm: Denial of Service in vllm-project/vllm |
Metrics |
ssvc
|
Tue, 15 Apr 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | vllm-project vllm version 0.5.2.2 is vulnerable to Denial of Service attacks. The issue occurs in the 'POST /v1/completions' and 'POST /v1/embeddings' endpoints. For 'POST /v1/completions', enabling 'use_beam_search' and setting 'best_of' to a high value causes the HTTP connection to time out, with vllm ceasing effective work and the request remaining in a 'pending' state, blocking new completion requests. For 'POST /v1/embeddings', supplying invalid inputs to the JSON object causes an issue in the background loop, resulting in all further completion requests returning a 500 HTTP error code ('Internal Server Error') until vllm is restarted. | ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-8939. Notes: All CVE users should reference CVE-2024-8939 instead of this CVE Record. All references and descriptions in this candidate have been removed to prevent accidental usage. |
Sat, 22 Mar 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Thu, 20 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | vllm-project vllm version 0.5.2.2 is vulnerable to Denial of Service attacks. The issue occurs in the 'POST /v1/completions' and 'POST /v1/embeddings' endpoints. For 'POST /v1/completions', enabling 'use_beam_search' and setting 'best_of' to a high value causes the HTTP connection to time out, with vllm ceasing effective work and the request remaining in a 'pending' state, blocking new completion requests. For 'POST /v1/embeddings', supplying invalid inputs to the JSON object causes an issue in the background loop, resulting in all further completion requests returning a 500 HTTP error code ('Internal Server Error') until vllm is restarted. | |
Title | Denial of Service in vllm-project/vllm | |
Weaknesses | CWE-400 | |
References |
| |
Metrics |
cvssV3_0
|

Status: REJECTED
Assigner: @huntr_ai
Published: 2025-03-20T10:10:55.762Z
Updated: 2025-04-15T15:53:31.930Z
Reserved: 2024-11-09T04:21:53.965Z
Link: CVE-2024-11040

Updated:

Status : Rejected
Published: 2025-03-20T10:15:23.293
Modified: 2025-04-15T16:15:21.517
Link: CVE-2024-11040
