PT-2026-81274 · Vllm · Vllm

·

CVE-2026-78684

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions vLLM versions prior to 0.27.0
Description The software fails to properly classify DeepStream as a GPU backend, which leads to the omission of pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream during a request to initialize the process-wide GPU decode pool and submit video content that bypasses resource controls, resulting in a partial denial of service for concurrent requests.
Recommendations Update vLLM to version 0.27.0 or later.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78684
GHSA-CQM8-JXG6-FQFQ

Affected Products

Vllm