CVE-2026-100651
- EPSS 0.31%
- Veröffentlicht 26.09.2026 13:23:21
- Zuletzt bearbeitet 06.10.2026 19:30:25
vLLM before 0.29.0 fails to enforce decoder prompt-length validation on the disaggregated serving endpoint /inference/v1/generate. When the request contains a 'features' (multimodal) payload, vllm/entrypoints/serve/disagg/serving.py builds a multimod...
CVE-2026-100650
- EPSS 0.61%
- Veröffentlicht 26.09.2026 13:23:20
- Zuletzt bearbeitet 06.10.2026 19:32:45
vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls (the VLLM_MAX_AUDIO_CLIP_FILESIZE_MB compressed-audio size cap, default 25 MB, and the per-modality --limit-mm-per-prompt item li...
CVE-2026-100649
- EPSS 0.31%
- Veröffentlicht 26.09.2026 13:23:19
- Zuletzt bearbeitet 06.10.2026 19:37:35
vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler subclass shadowing allows independent counter increments. Unauthenticated attackers can select different sampler subclasses in video ...
CVE-2026-100648
- EPSS 0.33%
- Veröffentlicht 26.09.2026 13:23:18
- Zuletzt bearbeitet 06.10.2026 19:40:20
vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing unauthenticated clients to bypass file size restrictions. Attackers can submit oversized audio files through chat endpoints to consu...
CVE-2026-100647
- EPSS 0.31%
- Veröffentlicht 26.09.2026 13:23:18
- Zuletzt bearbeitet 06.10.2026 19:46:06
vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-compatible and Anthropic API endpoints, which lacks maximum length validation and is processed on the single EngineCore scheduler thr...
CVE-2026-94627
- EPSS 0.45%
- Veröffentlicht 21.09.2026 22:04:16
- Zuletzt bearbeitet 29.09.2026 12:46:29
vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Attackers can trigger GPU memory exhaustion by submitt...
CVE-2026-94626
- EPSS 0.45%
- Veröffentlicht 21.09.2026 22:04:15
- Zuletzt bearbeitet 29.09.2026 12:46:53
vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggregate...
CVE-2026-94625
- EPSS 0.3%
- Veröffentlicht 21.09.2026 22:04:14
- Zuletzt bearbeitet 29.09.2026 12:47:01
vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send rejected requests to exhaust sender task pools, ...
CVE-2026-94624
- EPSS 0.45%
- Veröffentlicht 21.09.2026 22:04:13
- Zuletzt bearbeitet 29.09.2026 12:47:10
vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_...
CVE-2026-94623
- EPSS 0.45%
- Veröffentlicht 21.09.2026 22:04:12
- Zuletzt bearbeitet 29.09.2026 12:47:21
vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Att...