PT-2026-106272 · Vllm · Vllm

CVE-2026-105760

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions vLLM versions prior to 0.30.0
Description A partial denial of service issue exists in the OpenAI-compatible chat endpoint. A remote caller can provide large values for the fps and max frames variables within the media io kwargs field while selecting the GLMGA video backend. This allows the system to construct and deduplicate an excessively large pre-decode frame-index list in the shared media-loading executor, even if the provided video is very small. Consequently, a compact request can consume disproportionate CPU time and memory, delaying other unrelated media requests. This occurs because there is no strict upper bound on sampling work before the index list is constructed.
Recommendations Update to version 0.30.0. As a temporary workaround, remove or filter request-level video backend, fps, and max frames options at the gateway. Restrict untrusted callers from selecting the GLMGA backend. Apply authentication, rate limiting, request concurrency limits, and process memory isolation.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105760
GHSA-58V5-2M8F-94PR

Affected Products

Vllm