Database/AI/ML frameworks & serving
vLLM (`AsyncEngineRPCServer`): Unsafe deserialization on RPC entrypoints
CVE-2024-9053AI/ML frameworks & servingcurated
Impact
Unsafe deserialization on RPC entrypoints → RCE
Who can reach it
Unauthenticated network to the RPC server port
What to do
Upgrade past 0.6.0
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.