Miggo Logo

GHSA-j828-28rj-hfhp: vLLM vulnerable to Regular Expression Denial of Service

4.3

CVSS Score
3.1

Basic Information

CVE ID
-
EPSS Score
-
Published
5/28/2025
Updated
5/28/2025
KEV Status
No
Technology
TechnologyPython

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Package NameEcosystemVulnerable VersionsFirst Patched Version
vllmpip>= 0.6.3, < 0.9.00.9.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Summ*ry * r***nt r*vi*w i**nti*i** s*v*r*l r**ul*r *xpr*ssions in t** vllm *o****s* t**t *r* sus**pti*l* to R**ul*r *xpr*ssion **ni*l o* S*rvi** (R**oS) *tt**ks. T**s* p*tt*rns, i* *** wit* *r**t** or m*li*ious input, m*y **us* s*v*r* p*r*orm*n**

Reasoning

No *n*lysis *v*il**l*