PT-2026-102784 · Pypi · Vllm

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
vLLM before 0.29.0 validates allowed token ids against tokenizer length instead of model output logits width in SamplingParams. validate allowed token ids(). Attackers can supply token IDs above the output vocabulary that pass validation, causing LogitBiasState to corrupt GPU logits state and allow concurrent requests to sample tokens outside their allowlists.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-3998

Affected Products

Vllm