RULE(RULE ID:338760)

Rule General Information
Release Date: 2025-03-26
Rule Name: vLLM Denial of Service Vulnerability (CVE-2024-8939)
Severity:
CVE ID:
Rule Protection Details
Description: VLLM is an open-source high-throughput and memory efficient inference and service engine for LLM. VLLM 0.5.0.post1 and earlier versions have a resource management error vulnerability, which is caused by improper handling of the best_of parameter in the vllm JSON web API, resulting in a denial of service.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Refer to the announcement or patch by the vendor: https://github.com/vllm-project/vllm/releases/tag/v0.6.1.post2