Remote Memory Exhaustion in vLLM by VLLM Project
CVE-2026-100650

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100650?

The vLLM product, through version 0.29.0, suffers from a resource exhaustion vulnerability due to improper enforcement of media controls. When fetching remote or inline media, the system does not enforce the specified media limits until after the media has been fully retrieved and decoded. This flaw impacts several ingress points including media-acquisition layers and chat transcription services. A remote attacker can exploit this vulnerability, causing the server to allocate excessive memory and bandwidth proportional to the size of the media items requested. Depending on the ingress path, this could lead to service denial due to memory and bandwidth exhaustion. Although an API key is required for specific areas, the Rust frontend route is unauthenticated, increasing the risk of exploitation.

Affected Version(s)

vllm 0 < 0.29.0

vllm 0.29.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

KernelClint
jperezdealgaba
.