PT-2026-95873 · Vllm · Vllm
CVE-2026-93989
·
Published
2026-09-19
·
Updated
2026-09-23
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
vLLM versions prior to 0.29.1
Description
The software fails to properly validate
bad words token indices against the model's generation output width within the SamplingParams.update from tokenizer() function. This allows attackers to provide out-of-bounds token indices, which can corrupt the logits memory of concurrent requests. Consequently, other active HTTP requests may return incorrect tokens.Recommendations
Update vLLM to version 0.29.1 or later.
Exploit
Fix
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vllm