3.3
CVE-2026-90713
- EPSS 0.15%
- Veröffentlicht 14.09.2026 12:00:10
- Zuletzt bearbeitet 15.09.2026 14:17:33
- Erkennungen
vllm-project vLLM tiktoken vocab File mod.rs new denial of service
A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellervllm-project
≫
Produkt
vLLM
Version
0.1
Status
affected
Version
0.2
Status
affected
Version
0.3
Status
affected
Version
0.4
Status
affected
Version
0.5
Status
affected
Version
0.6
Status
affected
Version
0.7
Status
affected
Version
0.8
Status
affected
Version
0.9
Status
affected
Version
0.10
Status
affected
Version
0.11
Status
affected
Version
0.12
Status
affected
Version
0.13
Status
affected
Version
0.14
Status
affected
Version
0.15
Status
affected
Version
0.16
Status
affected
Version
0.17
Status
affected
Version
0.18
Status
affected
Version
0.19
Status
affected
Version
0.20
Status
affected
Version
0.21
Status
affected
Version
0.22
Status
affected
Version
0.23
Status
affected
Version
0.24
Status
affected
Version
0.25
Status
affected
Version
0.26
Status
affected
Version
0.27
Status
affected
Version
0.28
Status
affected
Version
0.29.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.048 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@vuldb.com | 1.9 | 0 | 0 |
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| cna@vuldb.com | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
|
| cna@vuldb.com | 1.7 | 3.1 | 2.9 |
AV:L/AC:L/Au:S/C:N/I:N/A:P
|
CWE-404 Improper Resource Shutdown or Release
The product does not release or incorrectly releases a resource before it is made available for re-use.
https://github.com/vllm-project/vllm/
https://vuldb.com/vuln/403267
https://vuldb.com/vuln/403267/cti
https://vuldb.com/cve/CVE-2026-90713
https://vuldb.com/submit/918762
https://github.com/vllm-project/vllm/issues/50954
https://github.com/vllm-project/vllm/pull/51135
https://gist.github.com/Yunzez/4b08ec3568a8cbfb120062e2558382b8