#VU119865 Resource exhaustion in vLLM - CVE-2025-61620
Published: December 11, 2025
vLLM
vLLM
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in multiple endpoints of the OpenAI-Compatible Server due to the ability to specify Jinja templates via the chat_template and chat_template_kwargs parameters. A remote user can trigger resource exhaustion and perform a denial of service (DoS) attack.