U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-11040

Change History

CVE Modified by huntr.dev 4/15/2025 12:15:21 PM

Action Type Old Value New Value
Changed Description
vllm-project vllm version 0.5.2.2 is vulnerable to Denial of Service attacks. The issue occurs in the 'POST /v1/completions' and 'POST /v1/embeddings' endpoints. For 'POST /v1/completions', enabling 'use_beam_search' and setting 'best_of' to a high value causes the HTTP connection to time out, with vllm ceasing effective work and the request remaining in a 'pending' state, blocking new completion requests. For 'POST /v1/embeddings', supplying invalid inputs to the JSON object causes an issue in the background loop, resulting in all further completion requests returning a 500 HTTP error code ('Internal Server Error') until vllm is restarted.
Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-8939. Notes: All CVE users should reference CVE-2024-8939 instead of this CVE Record. All references and descriptions in this candidate have been removed to prevent accidental usage.
Removed CVSS V3
huntr.dev: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

								
						
Removed CWE
huntr.dev: CWE-400

								
						
Removed Reference
huntr.dev: https://huntr.com/bounties/8ce20bbe-3c96-4cd1-97e5-25a5630925be

								
						

CVE Rejected by huntr.dev 4/15/2025 12:15:21 PM

Action Type Old Value New Value