Denial of Service Vulnerability in vLLM Product by vLLM Project
CVE-2026-100651
7.1HIGH
What is CVE-2026-100651?
The vLLM product prior to version 0.29.0 contains a vulnerability that allows exploitation through inadequate validation of prompt lengths on a specific endpoint. When submitting requests with features payloads, the system improperly generates EngineInput directly from user-supplied tokens, bypassing checks against maximum model lengths. Notably, this issue primarily affects multimodal processors configured to skip prompt length validation. An attacker could exploit this vulnerability to submit excessively long token_ids, potentially causing a worker to fail and resulting in Denial of Service. This issue has been resolved in version 0.29.0.
Affected Version(s)
vllm 0 < 0.29.0
vllm 0.29.0
