Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 8, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 8, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 8, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 8, 2025

      Xbox confirms it has “no minimum order quantity” or print limits for physical games — but there are other considerations

      May 8, 2025

      One of my favorite games is on sale, and it just had a huge update with a banger DLC

      May 8, 2025

      Palworld is forced to make “yet another compromise” in its ongoing legal battle with Nintendo — apologizing to players

      May 8, 2025

      As Windows 10’s death looms, Linux fans still promote “no ads or telemetry” for your old laptop instead of buying a Copilot+ PC

      May 8, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Mastering Node.js Streams: The Ultimate Guide to Memory-Efficient File Processing

      May 8, 2025
      Recent

      Mastering Node.js Streams: The Ultimate Guide to Memory-Efficient File Processing

      May 8, 2025

      Sitecore PowerShell commands – XM Cloud Content Migration

      May 8, 2025

      Our Partner Adobe Recognized Again as a DXP Leader

      May 8, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Xbox confirms it has “no minimum order quantity” or print limits for physical games — but there are other considerations

      May 8, 2025
      Recent

      Xbox confirms it has “no minimum order quantity” or print limits for physical games — but there are other considerations

      May 8, 2025

      One of my favorite games is on sale, and it just had a huge update with a banger DLC

      May 8, 2025

      Palworld is forced to make “yet another compromise” in its ongoing legal battle with Nintendo — apologizing to players

      May 8, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-30165 – vLLM ZeroMQ Remote Code Execution Vulnerability

    CVE-2025-30165 – vLLM ZeroMQ Remote Code Execution Vulnerability

    May 6, 2025

    CVE ID : CVE-2025-30165

    Published : May 6, 2025, 5:16 p.m. | 58 minutes ago

    Description : vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, vLLM uses ZeroMQ for some multi-node communication purposes. The secondary vLLM hosts open a `SUB` ZeroMQ socket and connect to an `XPUB` socket on the primary vLLM host. When data is received on this `SUB` socket, it is deserialized with `pickle`. This is unsafe, as it can be abused to execute code on a remote machine. Since the vulnerability exists in a client that connects to the primary vLLM host, this vulnerability serves as an escalation point. If the primary vLLM host is compromised, this vulnerability could be used to compromise the rest of the hosts in the vLLM deployment. Attackers could also use other means to exploit the vulnerability without requiring access to the primary vLLM host. One example would be the use of ARP cache poisoning to redirect traffic to a malicious endpoint used to deliver a payload with arbitrary code to execute on the target machine. Note that this issue only affects the V0 engine, which has been off by default since v0.8.0. Further, the issue only applies to a deployment using tensor parallelism across multiple hosts, which we do not expect to be a common deployment pattern. Since V0 is has been off by default since v0.8.0 and the fix is fairly invasive, the maintainers of vLLM have decided not to fix this issue. Instead, the maintainers recommend that users ensure their environment is on a secure network in case this pattern is in use. The V1 engine is not affected by this issue.

    Severity: 8.0 | HIGH

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Hostinger
    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-32022 – Finit Urandom Heap Buffer Overwrite Vulnerability
    Next Article CVE-2025-26262 – R-fx Networks Linux Malware Detect Arbitrary Code Execution and Privilege Escalation

    Related Posts

    Development

    Google Reports 75 Zero-Days Exploited in 2024 — 44% Targeted Enterprise Security Products

    May 8, 2025
    Development

    SonicWall Confirms Active Exploitation of Flaws Affecting Multiple Appliance Models

    May 8, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    binafy/laravel-stub

    Development

    The Design Dilemma: Startup Success and User Satisfaction

    Development

    Overview of.NET MAUI: Easily Developing Cross-Platform Applications

    Development

    CVE-2025-32961 – Cuba JPA Cross-Site Scripting (XSS)

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    TextMagic: Revolutionizing Text Editing Beyond HTML Input and TextArea!

    July 13, 2024

    Comments Source: Read More 

    Preparing for 2025: Microsoft’s Plan to Secure Digital Identities and Defend Against Emerging Cyber Attacks

    January 29, 2025

    Website Performance Optimization: You Don’t Need 20 Tips

    January 30, 2025

    Amazon’s Kindle download deadline is in two days — Here’s how I saved my ebooks

    February 25, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.