vLLM allows clients to crash the openai server with invalid regex
Moderate severity
GitHub Reviewed
Published
May 28, 2025
in
vllm-project/vllm
•
Updated May 30, 2025
Description
Published to the GitHub Advisory Database
May 28, 2025
Reviewed
May 28, 2025
Published by the National Vulnerability Database
May 30, 2025
Last updated
May 30, 2025
Impact
A denial of service bug caused the vLLM server to crash if an invalid regex was provided while using structured output. This vulnerability is similar to GHSA-6qc9-v4r8-22xg, but for regex instead of a JSON schema.
Issue with more details: vllm-project/vllm#17313
Patches
References