PT-2026-106270 · Vllm · Vllm
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
vLLM versions 0.24.0 through 0.29.1rc0
Description
An unauthenticated remote attacker can cause a denial of service by exhausting the memory of the API-server process. This occurs when deployments serving Qwen2-VL or Qwen3-VL models accept request-level values for
media io kwargs.video.max frames and media io kwargs.video.fps without enforcing server-side limits. An attacker can submit these values to the /tokenize endpoint, forcing the sampler to decode an excessive number of frames from a controlled video input. This leads to disproportionate frontend memory consumption and can terminate the API process before scheduling or admission control takes place. The issue is specifically present in the Qwen2VLVideoBackend and Qwen3VLVideoBackend classes. The Rust frontend is not affected as it rejects the media io kwargs field.Recommendations
Update vLLM to version 0.30.0.
As a temporary mitigation, restrict access to the
/tokenize endpoint or avoid using the media io kwargs.video.max frames and media io kwargs.video.fps parameters in requests.Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vllm