THREAT OPS › Threat News › [GHSA] GHSA-pr7f-p5mw-fc87 (medium) — vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
[GHSA] GHSA-pr7f-p5mw-fc87 (medium) — vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
GHSA-pr7f-p5mw-fc87 Severity: medium CVE: CVE-2026-73557
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
## Executive Summary
The follow-up protection for CVE-2025-62164 is incomplete at vLLM revision `26587f9519e22a5c4549ead7595ad9ca3229c4fd`. It wraps serialized prompt-embedding reconstruction and dense conversion in `torch.sparse.check_sparse_tensor_in
Indicators of compromise
- 26587f9519e22a5c4549ead7595ad9ca3229c4fdsha1
- 58fab50d82838d5014f4a14d991fdb9352c9c84bsha1
- 84e23d103d3483f944780d0d42bcf0993fd27e3asha1
- f0a1c8453ad1c664c8a04c83fe545195fcd556ebsha1
- 14043dfecd35dd2f12b4d51eb9fa166184a0ca0fsha1
- CVE-2025-62164cve
- CVE-2026-73557cve
Original source: https://github.com/advisories/GHSA-pr7f-p5mw-fc87