PT-2026-99325 · Vllm · Vllm
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
vLLM versions prior to 0.29.0
Description
The software fails to validate if the values provided in
stop token ids are within the model vocabulary or logits range, checking only that they are integers. When min tokens is greater than 0, these IDs are used as logits indices to suppress stop tokens. An out-of-range ID triggers a CUDA indexing operation (index put ), leading to a device-side assertion. An authenticated API user can exploit this by sending a malformed request to the 'POST /v1/completions' or 'POST /v1/chat/completions' endpoints, resulting in a 500 Internal Server Error and placing the EngineCore into a fatal state. This causes a denial of service where subsequent requests fail until the service is restarted. Real-world incidents of this issue being exploited have been reported.Recommendations
Update vLLM to version 0.29.0 or later.
Exploit
Fix
DoS
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vllm