Vllm · Vllm · CVE-2026-100650
**Name of the Vulnerable Software and Affected Versions**
vLLM versions prior to 0.29.1
**Description**
The server fetches and fully materializes remote or inline media before enforcing media controls, such as the `VLLM MAX AUDIO CLIP FILESIZE MB` size cap and the `--limit-mm-per-prompt` item limits. This occurs across four ingress paths: the shared media-acquisition layer `HTTPConnection.get bytes()`/`async get bytes()`, the chat completions `audio url`/`base64` path, the batch speech runner, and the Rust frontend `POST /tokenize` route. Because the server reads the entire HTTP response body or base64-decodes the payload before applying limits, a remote attacker can cause memory allocation and outbound bandwidth consumption proportional to the chosen body size or media item count. This leads to pre-inference memory and bandwidth exhaustion, resulting in a denial of service. While chat and batch surfaces may require an API key, the `POST /tokenize` route is unauthenticated.
**Recommendations**
Update to a version later than 0.29.0.
Restrict access to the `POST /tokenize` route to minimize the risk of unauthenticated exploitation.