CVE-2025-32444
CVSS 3.1 Score 10 of 10 (high)
Details
Summary
CVE-2025-32444 is a remote code execution vulnerability affecting versions 0.6.5 and prior to 0.8.5 of the vLLM inference and serving engine for Large Language Models. The issue arises from the use of pickle-based serialization over insecure ZeroMQ sockets during mooncake integration. This vulnerability allows an attacker to execute arbitrary code, as the sockets were configured to accept connections on all network interfaces. Not all vLLM instances are at risk, as those without the mooncake integration remain unaffected. The vulnerability has been addressed and fixed in version 0.8.5.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- vLLM