Resource Limit Bypass in vLLM by vLLM Project
CVE-2026-100649

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100649?

Versions of vLLM prior to 0.29.0 include a vulnerability in the PyNvVideoCodec decoder. This issue stems from sampler subclass shadowing that allows attackers without authentication to manipulate video requests, selecting different sampler subclasses to bypass fixed decoder limits. Consequently, this can exhaust the GPU memory not accounted for, potentially crippling system performance and stability.

Affected Version(s)

vllm 0 < 0.29.0

vllm 0.29.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

JPengLi
jperezdealgaba
.