CVE-2025-62164
Chainguard vulnerability analysis and mitigation

vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability could lead to a crash (denial-of-service) and potentially remote code execution (RCE), exists in the Completions API endpoint. When processing user-supplied prompt embeddings, the endpoint loads serialized tensors using torch.load() without sufficient validation. Due to a change introduced in PyTorch 2.8.0, sparse tensor integrity checks are disabled by default. As a result, maliciously crafted tensors can bypass internal bounds checks and trigger an out-of-bounds memory write during the call to to_dense(). This memory corruption can crash vLLM and potentially lead to code execution on the server hosting vLLM. This issue has been patched in version 0.11.1.


SourceNVD

Related Chainguard vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-69229MEDIUM6.6
  • WolfiWolfi
  • py3-cassandra-medusa
NoYesJan 06, 2026
CVE-2025-69228MEDIUM6.6
  • WolfiWolfi
  • py3-cassandra-medusa
NoYesJan 06, 2026
CVE-2025-69227MEDIUM6.6
  • WolfiWolfi
  • apache-beam-python-3.11-sdk
NoYesJan 06, 2026
CVE-2025-69230LOW2.7
  • WolfiWolfi
  • py3-aiohttp
NoYesJan 06, 2026
CVE-2025-69225LOW2.7
  • WolfiWolfi
  • py3-cassandra-medusa
NoYesJan 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management