CVE-2025-71379 - CVE House
Back to Database
Status published Medium CVE-2025-71379

vllm - Regular Expression Denial of Service in Multiple Components

Vulnerability Description

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compatible serving chat endpoint — are susceptible to catastrophic backtracking. An attacker submitting crafted input with nested or repeated structures can trigger severe CPU consumption and performance degradation, resulting in denial of service.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-71379

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • kexinoh
  • russellb
  • mgoin

Affected Vendor

Affected Software

vllm
Vulnerable Versions:
0.6.3, 0.9.0

Timeline

Official Publish: June 20th, 2026
Last Modified: June 22nd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)