Remote Memory Exhaustion in vLLM by VLLM Project
CVE-2026-100650
What is CVE-2026-100650?
The vLLM product, through version 0.29.0, suffers from a resource exhaustion vulnerability due to improper enforcement of media controls. When fetching remote or inline media, the system does not enforce the specified media limits until after the media has been fully retrieved and decoded. This flaw impacts several ingress points including media-acquisition layers and chat transcription services. A remote attacker can exploit this vulnerability, causing the server to allocate excessive memory and bandwidth proportional to the size of the media items requested. Depending on the ingress path, this could lead to service denial due to memory and bandwidth exhaustion. Although an API key is required for specific areas, the Rust frontend route is unauthenticated, increasing the risk of exploitation.
Affected Version(s)
vllm 0 < 0.29.0
vllm 0.29.0
