PT-2026-55999 · Vllm · Vllm

·

CVE-2026-55514

·

Published

2026-07-06

·

Updated

2026-07-20

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions vLLM versions 0.12.0 through 0.23.x
Description A flaw in the EngineCore of the library occurs when a remote authorized user sends a pure prompt embeds payload to the '/v1/completions' endpoint using a model that implements M-RoPE (Multimodal Rotary Positional Embedding). This action triggers an assertion failure, resulting in a fatal crash that shuts down the entire server application.
Recommendations Update to version 0.24.0.

Exploit

Fix

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55514
GHSA-33CG-GXV8-3P8G
PYSEC-2026-2303

Affected Products

Vllm