PT-2026-99323 · Vllm · Vllm
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
vLLM versions 0.22.0 through 0.23.0
Description
The Rust HTTP and gRPC frontends fail to validate
stop token ids against vocabulary bounds, allowing out-of-vocabulary token IDs to reach the MinTokensLogitsProcessor function. An attacker can submit requests where min tokens is greater than zero and stop token ids are out-of-vocabulary, triggering CUDA tensor indexing failures. This results in the EngineCore entering a fatal state, which necessitates a service restart.Recommendations
Update vLLM versions 0.22.0 through 0.23.0 to a newer version that implements proper validation for
stop token ids.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vllm