« Back to list

CVE-2024-8768

Status: DeferredHigh (7.5)—

A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2024-8768",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-8768",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-17T18:21:27.413720Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.5.5",
              "versionType": "custom"
            }
          ],
          "packageName": "vllm",
          "collectionURL": "https://github.com/vllm-project/vllm",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:enterprise_linux_ai:1"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux AI (RHEL AI)",
          "packageName": "rhelai1/bootc-nvidia-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:enterprise_linux_ai:1"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux AI (RHEL AI)",
          "packageName": "rhelai1/instructlab-nvidia-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-09-17T17:15:11.100",
  "references": [
    {
      "url": "https://access.redhat.com/security/cve/CVE-2024-8768",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2311895",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://github.com/vllm-project/vllm/issues/7632",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://github.com/vllm-project/vllm/pull/7746",
      "source": "secalert@redhat.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-617"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service."
    },
    {
      "lang": "es",
      "value": "Se encontró una falla en la librería vLLM. Una solicitud de API de finalización con un mensaje vacío bloqueará el servidor de API de vLLM, lo que provocará una denegación de servicio."
    }
  ],
  "lastModified": "2026-06-17T08:23:16.037",
  "sourceIdentifier": "secalert@redhat.com"
}