SOURCE-LINKED INTELLIGENCE
GHSA-mcmc-2m55-j8jj: vLLM introduced enhanced protection for CVE-2025-62164
### Summary The fix [here](https://github.com/vllm-project/vllm/pull/27204) for CVE-2025-62164 is not sufficient. The fix only disables prompt embeds by default rather than addressing the root cause, so the DoS vulnerability remains when the feature is enabled. ### Details vLLM's pending change attempts to fix the root cause, which is the missing sparse tensor validation. PyTorch (~v2.0) disables sparse tensor validation (specifically, sparse tensor invariants checks) by default for performance reasons. vLLM is adding the sparse tensor validation to ensure indices are valid, non-negative, and
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2026-01-08T21:47:43.000Z
- OSV AI package advisories · 2026-06-20T19:16:23.567Z
First collected: 2026-09-20T22:31:48.298Z. This is not the publication date.