PT-2026-95639 · Vllm · Vllm

·

CVE-2026-93840

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions vLLM versions prior to 0.29.0
Description The SamplingParams. validate allowed token ids() function validates allowed token ids against the tokenizer length rather than the model output logits width. This allows attackers to provide token IDs that exceed the output vocabulary but still pass validation. Consequently, the LogitBiasState can corrupt the GPU logits state, enabling concurrent requests to sample tokens that are outside their designated allowlists.
Recommendations Update vLLM to version 0.29.0 or later.

Exploit

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93840
PYSEC-2026-3998

Affected Products

Vllm