Beveiligingsadvies

CVE-2025-29783

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-03-19 15:33:28
Laatst bijgewerkt 2025-03-22 00:02:54
Toegewezen door GitHub_M
CVSS-score 9.1
Status PUBLISHED

Beschrijving

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Mooncake, unsafe deserialization exposed directly over ZMQ/TCP on all network interfaces will allow attackers to execute remote code on distributed hosts. This is a remote code execution vulnerability impacting any deployments using Mooncake to distribute KV across distributed hosts. This vulnerability is fixed in 0.8.0.