PT-2026-81274 · Vllm · Vllm
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
vLLM versions prior to 0.27.0
Description
The software fails to properly classify DeepStream as a GPU backend, which leads to the omission of pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream during a request to initialize the process-wide GPU decode pool and submit video content that bypasses resource controls, resulting in a partial denial of service for concurrent requests.
Recommendations
Update vLLM to version 0.27.0 or later.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vllm