PT-2026-93837 · Vllm · Vllm
CVE-2026-57173
·
Published
2026-09-16
·
Updated
2026-10-01
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
vLLM versions prior to 0.24.0
Description
An issue exists in the audio handling path for the
/v1/chat/completions endpoint where the input audio content is processed without a duration limit. Specifically, the AudioMediaIO.load bytes() and AudioMediaIO.load file() functions call the shared audio decoder without passing the VLLM MAX AUDIO DECODE DURATION S variable. This allows an unauthenticated client to submit a small compressed audio file that expands into a massive float32 PCM allocation during decoding, bypassing the duration guards used in other paths. This memory amplification can lead to an out-of-memory (OOM) worker crash, resulting in a remote denial of service. Additionally, inline data URLs can reach this path without being restricted by the VLLM AUDIO FETCH TIMEOUT setting. This issue affects any deployment serving an audio-capable model.Recommendations
Update vLLM to version 0.24.0.
As a temporary mitigation, restrict access to the
/v1/chat/completions endpoint or implement authentication to limit reachability.Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vllm