PT-2026-93785 · Vllm · Vllm
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X |
Name of the Vulnerable Software and Affected Versions
vllm versions prior to 0.30.0
Description
A remote attack can be launched against the
vllm/v1/sample/thinking budget state.py file, leading to inefficient algorithmic complexity. This condition occurs when certain functionality within the file is manipulated, causing the system to consume resources inefficiently.Recommendations
Update to version 0.30.0.
Exploit
Fix
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vllm