{"id":"CVE-2024-9052","aliases":["PYSEC-2026-568"],"url":"https://o3.security/vulnerability/CVE-2024-9052","summary":"vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object","details":"vllm-project vllm version 0.6.0 contains a vulnerability in the distributed training API. The function vllm.distributed.GroupCoordinator.recv_object() deserializes received object bytes using pickle.loads() without sanitization, leading to a remote code execution vulnerability.\n\n### Maintainer perspective\nNote that vLLM does NOT use the code as described in the report on huntr. The problem only exists if you use these internal APIs in a way that exposes them to a network as described. The vllm team was not involved in the analysis of this report and the decision to assign it a CVE.","published":"2025-03-20T12:32:50Z","modified":"2026-08-07T08:12:14.510898569Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"vllm","fixedVersion":null}],"fix":{"url":"https://github.com/github/advisory-database/pull/5444","label":"github/advisory-database#5444"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-9052"},{"type":"WEB","url":"https://github.com/github/advisory-database/pull/5444"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/blob/32e7db25365415841ebc7c4215851743fbb1bad1/vllm/distributed/parallel_state.py#L480"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/blob/v0.8.1/vllm/distributed/parallel_state.py#L457"},{"type":"WEB","url":"https://huntr.com/bounties/ea75728f-4efe-4a3d-9f53-33f2c908e9f8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T08:12:14.510898569Z"}}