5.3
CVE-2026-105760
- EPSS 0.3%
- Veröffentlicht 05.10.2026 23:01:54
- Zuletzt bearbeitet 06.10.2026 15:17:15
- Erkennungen
vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, a caller can use the request-level media_io_kwargs field to select the GLMGA video backend and supply large values for the fps and max_frames options without a strict work ceiling. GLMGA constructs and deduplicates an attacker-sized pre-decode frame-index list, allowing a compact request and tiny valid video to consume disproportionate CPU time and memory in the shared media-loading executor. This issue is fixed in version 0.30.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellervllm-project
≫
Produkt
vllm
Version
>= 0.23.0rc2, < 0.30.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.209 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
https://github.com/vllm-project/vllm/releases/tag/v0.30.0
https://github.com/vllm-project/vllm/security/advisories/GHSA-58v5-2m8f-94pr
https://github.com/vllm-project/vllm/pull/54935
https://github.com/vllm-project/vllm/commit/8b6de0eb9a09ef53f20cf06bd4d17ee264b9c2a7