PT-2026-95371 · Vllm · Vllm

·

CVE-2026-93592

·

Published

2026-09-18

·

Updated

2026-09-22

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions vLLM versions prior to 0.28.0
Description The software fails to validate the lower bound of token IDs in the '/v1/embeddings' and '/pooling' endpoints. This allows unauthenticated attackers to crash the engine by submitting negative token IDs. A single request containing a negative token ID triggers a CUDA device-side assertion, which poisons the GPU context and causes all subsequent requests to fail until the process is restarted.
Recommendations Update vLLM to version 0.28.0 or later. Avoid submitting negative values to the token ID parameter in the '/v1/embeddings' and '/pooling' endpoints.

Exploit

Fix

DoS

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93592
GHSA-25Q3-V2HM-8VPF
PYSEC-2026-3997

Affected Products

Vllm