Resource Limit Bypass in vLLM by vLLM Project
CVE-2026-100649
6.3MEDIUM
What is CVE-2026-100649?
Versions of vLLM prior to 0.29.0 include a vulnerability in the PyNvVideoCodec decoder. This issue stems from sampler subclass shadowing that allows attackers without authentication to manipulate video requests, selecting different sampler subclasses to bypass fixed decoder limits. Consequently, this can exhaust the GPU memory not accounted for, potentially crippling system performance and stability.
Affected Version(s)
vllm 0 < 0.29.0
vllm 0.29.0
