PT-2026-106324 · Vllm · Vllm

·

CVE-2026-105775

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv ssm forward of the file vllm/model executor/layers/mamba/mamba mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Exploit

Fix

Buffer Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105775

Affected Products

Vllm