PT-2026-55999 · Vllm · Vllm
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
vLLM versions 0.12.0 through 0.23.x
Description
A flaw in the EngineCore of the library occurs when a remote authorized user sends a pure prompt embeds payload to the '/v1/completions' endpoint using a model that implements M-RoPE (Multimodal Rotary Positional Embedding). This action triggers an assertion failure, resulting in a fatal crash that shuts down the entire server application.
Recommendations
Update to version 0.24.0.
Exploit
Fix
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vllm