PT-2026-106270 · Vllm · Vllm

·

CVE-2026-105758

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions vLLM versions 0.24.0 through 0.29.1rc0
Description An unauthenticated remote attacker can cause a denial of service by exhausting the memory of the API-server process. This occurs when deployments serving Qwen2-VL or Qwen3-VL models accept request-level values for media io kwargs.video.max frames and media io kwargs.video.fps without enforcing server-side limits. An attacker can submit these values to the /tokenize endpoint, forcing the sampler to decode an excessive number of frames from a controlled video input. This leads to disproportionate frontend memory consumption and can terminate the API process before scheduling or admission control takes place. The issue is specifically present in the Qwen2VLVideoBackend and Qwen3VLVideoBackend classes. The Rust frontend is not affected as it rejects the media io kwargs field.
Recommendations Update vLLM to version 0.30.0. As a temporary mitigation, restrict access to the /tokenize endpoint or avoid using the media io kwargs.video.max frames and media io kwargs.video.fps parameters in requests.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105758
GHSA-X6MC-67GF-CHW4

Affected Products

Vllm