vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with a model using M-RoPE causes EngineCore to fail an assertion and fatally crash, shutting down the entire server application. Any remote user who is authorized to make a /v1/completions request can make such a request and induce a crash. This issue is fixed in version 0.24.0.
References
| Link | Resource |
|---|---|
| https://github.com/vllm-project/vllm/commit/470229c37efaf69c86e8bc97482b0b1ff7551c65 | Patch |
| https://github.com/vllm-project/vllm/pull/45252 | Issue Tracking Patch |
| https://github.com/vllm-project/vllm/releases/tag/v0.24.0 | Release Notes |
| https://github.com/vllm-project/vllm/security/advisories/GHSA-33cg-gxv8-3p8g | Vendor Advisory |
Configurations
History
07 Jul 2026, 19:02
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Vllm
Vllm vllm |
|
| CPE | cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| References | () https://github.com/vllm-project/vllm/commit/470229c37efaf69c86e8bc97482b0b1ff7551c65 - Patch | |
| References | () https://github.com/vllm-project/vllm/pull/45252 - Issue Tracking, Patch | |
| References | () https://github.com/vllm-project/vllm/releases/tag/v0.24.0 - Release Notes | |
| References | () https://github.com/vllm-project/vllm/security/advisories/GHSA-33cg-gxv8-3p8g - Vendor Advisory |
06 Jul 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-06 21:16
Updated : 2026-07-07 19:02
NVD link : CVE-2026-55514
Mitre link : CVE-2026-55514
CVE.ORG link : CVE-2026-55514
JSON object : View
Products Affected
vllm
- vllm
CWE
CWE-617
Reachable Assertion
