CVE-2024-8768
Status: DeferredHigh (7.5)—
A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.68%
- Percentile among all scored CVEs: 51
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-617
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-8768",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-8768",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-09-17T18:21:27.413720Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "0.5.5",
"versionType": "custom"
}
],
"packageName": "vllm",
"collectionURL": "https://github.com/vllm-project/vllm",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:enterprise_linux_ai:1"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux AI (RHEL AI)",
"packageName": "rhelai1/bootc-nvidia-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:enterprise_linux_ai:1"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux AI (RHEL AI)",
"packageName": "rhelai1/instructlab-nvidia-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
}
]
}
],
"published": "2024-09-17T17:15:11.100",
"references": [
{
"url": "https://access.redhat.com/security/cve/CVE-2024-8768",
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2311895",
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/vllm-project/vllm/issues/7632",
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/vllm-project/vllm/pull/7746",
"source": "secalert@redhat.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-617"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service."
},
{
"lang": "es",
"value": "Se encontró una falla en la librería vLLM. Una solicitud de API de finalización con un mensaje vacío bloqueará el servidor de API de vLLM, lo que provocará una denegación de servicio."
}
],
"lastModified": "2026-06-17T08:23:16.037",
"sourceIdentifier": "secalert@redhat.com"
}