Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ecmgit

#32865of 57,657
8.7Total CVSS
Vulnerabilities · 1
PT-2026-95371
8.7
2026-09-18
Vllm · Vllm · CVE-2026-93592
**Name of the Vulnerable Software and Affected Versions** vLLM versions prior to 0.28.0 **Description** The software fails to validate the lower bound of token IDs in the '/v1/embeddings' and '/pooling' endpoints. This allows unauthenticated attackers to crash the engine by submitting negative token IDs. A single request containing a negative token ID triggers a CUDA device-side assertion, which poisons the GPU context and causes all subsequent requests to fail until the process is restarted. **Recommendations** Update vLLM to version 0.28.0 or later. Avoid submitting negative values to the token ID parameter in the '/v1/embeddings' and '/pooling' endpoints.