PT-2026-99321 · Vllm · Vllm
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
vLLM versions prior to 0.29.1
Description
The server fetches and fully materializes remote or inline media before enforcing media controls, such as the
VLLM MAX AUDIO CLIP FILESIZE MB size cap and the --limit-mm-per-prompt item limits. This occurs across four ingress paths: the shared media-acquisition layer HTTPConnection.get bytes()/async get bytes(), the chat completions audio url/base64 path, the batch speech runner, and the Rust frontend POST /tokenize route. Because the server reads the entire HTTP response body or base64-decodes the payload before applying limits, a remote attacker can cause memory allocation and outbound bandwidth consumption proportional to the chosen body size or media item count. This leads to pre-inference memory and bandwidth exhaustion, resulting in a denial of service. While chat and batch surfaces may require an API key, the POST /tokenize route is unauthenticated.Recommendations
Update to a version later than 0.29.0.
Restrict access to the
POST /tokenize route to minimize the risk of unauthenticated exploitation.Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vllm