PT-2026-99323 · Vllm · Vllm

·

CVE-2026-100652

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions vLLM versions 0.22.0 through 0.23.0
Description The Rust HTTP and gRPC frontends fail to validate stop token ids against vocabulary bounds, allowing out-of-vocabulary token IDs to reach the MinTokensLogitsProcessor function. An attacker can submit requests where min tokens is greater than zero and stop token ids are out-of-vocabulary, triggering CUDA tensor indexing failures. This results in the EngineCore entering a fatal state, which necessitates a service restart.
Recommendations Update vLLM versions 0.22.0 through 0.23.0 to a newer version that implements proper validation for stop token ids.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100652
GHSA-QFF2-492F-9FM4
PYSEC-2026-4185

Affected Products

Vllm