PT-2026-51172 · Vllm+1 · Vllm+1

·

CVE-2026-56340

·

Published

2026-01-08

·

Updated

2026-06-21

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vLLM versions 0.10.2 through 0.12.x
Description Multimodal embeddings processing lacks sparse tensor validation. Since PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests containing malformed tensor indices, such as negative or out-of-bounds values, when the prompt-embeds feature is enabled. This can lead to crashes, resource exhaustion resulting in denial of service, or potential out-of-bounds/write-what-where memory corruption.
Recommendations Update to version 0.13.0 or later. As a temporary workaround, disable the prompt-embeds feature to minimize the risk of exploitation.

Exploit

Fix

DoS

Deserialization of Untrusted Data

RCE

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56340
GHSA-78FP-CF4H-G36P
GHSA-MCMC-2M55-J8JJ
PYSEC-2026-250

Affected Products

Pytorch
Vllm