Appsecure logo

CVE-2025-32444: Critical Vulnerability in vllm

A critical remote code execution vulnerability has been identified in vllm versions prior to 0.8.5. Organizations using affected versions should prioritize patching to prevent potential exploitation through unsecured ZeroMQ sockets.

CRITICALCVSS 10 · Published April 30, 2025

Not a customer? See how AppSecure simulates real world attacks to protect your infrastructure.

Speak to Experts

This vulnerability allows remote code execution in vllm versions starting from 0.6.5 and prior to 0.8.5. The vulnerability arises from the use of pickle-based serialization over unsecured ZeroMQ sockets, which were configured to listen on all network interfaces, thereby increasing the risk of exploitation. As a result, attackers can potentially access these vulnerable sockets and execute arbitrary code remotely. Organizations utilizing vllm without the mooncake integration are not affected by this vulnerability.

The severity of this vulnerability is classified as critical, with a CVSS score of 10.0, indicating a high likelihood of successful exploitation. The urgency for organizations to address this issue is paramount, as the potential risk includes significant impacts on confidentiality, integrity, and availability.

Although there is currently no known exploit available for this vulnerability, the nature of remote code execution vulnerabilities means that they can be rapidly developed by malicious actors. Organizations should prioritize patching to version 0.8.5, where this issue has been addressed.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Latest CVEs. Recently published vulnerabilities from the NVD database.

View all vulnerabilities
CVE IDSeverity
CVE-2025-65418HIGH
CVE-2025-65417MEDIUM
CVE-2025-65416MEDIUM
CVE-2025-65415MEDIUM
CVE-2025-61314HIGH

Protect Your Business with Hacker-Focused Approach.