PT-2026-99321 · Vllm · Vllm

·

CVE-2026-100650

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions vLLM versions prior to 0.29.1
Description The server fetches and fully materializes remote or inline media before enforcing media controls, such as the VLLM MAX AUDIO CLIP FILESIZE MB size cap and the --limit-mm-per-prompt item limits. This occurs across four ingress paths: the shared media-acquisition layer HTTPConnection.get bytes()/async get bytes(), the chat completions audio url/base64 path, the batch speech runner, and the Rust frontend POST /tokenize route. Because the server reads the entire HTTP response body or base64-decodes the payload before applying limits, a remote attacker can cause memory allocation and outbound bandwidth consumption proportional to the chosen body size or media item count. This leads to pre-inference memory and bandwidth exhaustion, resulting in a denial of service. While chat and batch surfaces may require an API key, the POST /tokenize route is unauthenticated.
Recommendations Update to a version later than 0.29.0. Restrict access to the POST /tokenize route to minimize the risk of unauthenticated exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100650
GHSA-P6G9-7V3X-M8MV

Affected Products

Vllm