vllm is vulnerable to Regular Expression Denial of Service (ReDoS)
53
Medium Risk
The lm-format-enforcer structured-output backend compiles a user-supplied regular expression into a finite-state machine without a compile timeout or buildability check. A single request containing a catastrophic pattern pegs a CPU core during grammar compilation and stalls the structured-output engine path. This blocks concurrent requests and causes denial of service. The fix routes the compile through the same timeout guard already applied to the other structured-output backends.
You are affected if you are using a version that falls within the vulnerable range and you have selected the lm-format-enforcer structured outputs backend and accept user-controlled regular expressions.
vllm is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 0.10.2 - 0.25.1.
Upgrade the vllm library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant