PT-2026-93837 · Vllm · Vllm

CVE-2026-57173

·

Published

2026-09-16

·

Updated

2026-10-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions vLLM versions prior to 0.24.0
Description An issue exists in the audio handling path for the /v1/chat/completions endpoint where the input audio content is processed without a duration limit. Specifically, the AudioMediaIO.load bytes() and AudioMediaIO.load file() functions call the shared audio decoder without passing the VLLM MAX AUDIO DECODE DURATION S variable. This allows an unauthenticated client to submit a small compressed audio file that expands into a massive float32 PCM allocation during decoding, bypassing the duration guards used in other paths. This memory amplification can lead to an out-of-memory (OOM) worker crash, resulting in a remote denial of service. Additionally, inline data URLs can reach this path without being restricted by the VLLM AUDIO FETCH TIMEOUT setting. This issue affects any deployment serving an audio-capable model.
Recommendations Update vLLM to version 0.24.0. As a temporary mitigation, restrict access to the /v1/chat/completions endpoint or implement authentication to limit reachability.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57173
GHSA-HCWQ-8WJF-3GCR
PYSEC-2026-4179

Affected Products

Vllm