7.5

CVE-2026-103241

Exploit

vllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of service

A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 0.29.1rc0 is able to resolve this issue. This patch is called 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vllm ≫ Vllm Version <= 0.26.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.66% 0.497
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cna@vuldb.com 5.5 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cna@vuldb.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
cna@vuldb.com 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-404 Improper Resource Shutdown or Release

The product does not release or incorrectly releases a resource before it is made available for re-use.

https://github.com/vllm-project/vllm/
Product
https://vuldb.com/vuln/411965
Third Party Advisory
VDB Entry
https://vuldb.com/vuln/411965/cti
VDB Entry
Permissions Required
https://vuldb.com/cve/CVE-2026-103241
Third Party Advisory
VDB Entry
https://vuldb.com/submit/956250
Third Party Advisory
VDB Entry
https://github.com/vllm-project/vllm/issues/50927
Patch
Issue Tracking
https://github.com/vllm-project/vllm/pull/54303
Patch
Issue Tracking
https://gist.github.com/Yunzez/8e98d656aa667095b513161eb056d28e
Product
https://github.com/vllm-project/vllm/commit/3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9
Patch
https://github.com/vllm-project/vllm/releases/tag/v0.29.1rc0
Release Notes