#VU118093 Resource exhaustion in vLLM - CVE-2025-48956
Published: November 4, 2025
vLLM
vLLM
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when parsing HTTP header values. A remote attacker can send a specially crafted HTTP request with an overly large header value (e.g. for X-Forwarded-For header) to trigger resource exhaustion and perform a denial of service (DoS) attack.