VYPR

Vllm

by Pypi

CVEs (1)

  • CVE-2026-56340Jun 20, 2026
    risk 0.00cvss epss

    vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests with malformed (negative or out-of-bounds) tensor…