CVE-2026-55514

vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with a model using M-RoPE causes EngineCore to fail an assertion and fatally crash, shutting down the entire server application. Any remote user who is authorized to make a /v1/completions request can make such a request and induce a crash. This issue is fixed in version 0.24.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*

History

07 Jul 2026, 19:02

Type Values Removed Values Added
First Time Vllm
Vllm vllm
CPE cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://github.com/vllm-project/vllm/commit/470229c37efaf69c86e8bc97482b0b1ff7551c65 - () https://github.com/vllm-project/vllm/commit/470229c37efaf69c86e8bc97482b0b1ff7551c65 - Patch
References () https://github.com/vllm-project/vllm/pull/45252 - () https://github.com/vllm-project/vllm/pull/45252 - Issue Tracking, Patch
References () https://github.com/vllm-project/vllm/releases/tag/v0.24.0 - () https://github.com/vllm-project/vllm/releases/tag/v0.24.0 - Release Notes
References () https://github.com/vllm-project/vllm/security/advisories/GHSA-33cg-gxv8-3p8g - () https://github.com/vllm-project/vllm/security/advisories/GHSA-33cg-gxv8-3p8g - Vendor Advisory

06 Jul 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-06 21:16

Updated : 2026-07-07 19:02


NVD link : CVE-2026-55514

Mitre link : CVE-2026-55514

CVE.ORG link : CVE-2026-55514


JSON object : View

Products Affected

vllm

  • vllm
CWE
CWE-617

Reachable Assertion