Uncontrolled Resource Consumption in VLLM Multimodal Chat by VLLM Project
CVE-2026-100648

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100648?

Prior to version 0.29.0, VLLM fails to enforce the VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit during multimodal chat audio decoding. This oversight permits unauthenticated clients to circumvent file size limitations, enabling attackers to upload excessively large audio files through chat endpoints. Consequently, this can lead to significant memory and CPU resource consumption during the decoding process, potentially disrupting service availability and performance.

Affected Version(s)

vllm 0 < 0.29.0

vllm 0.29.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
jperezdealgaba
.