Denial of Service Vulnerability in vLLM Product by vLLM Project
CVE-2026-100651

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100651?

The vLLM product prior to version 0.29.0 contains a vulnerability that allows exploitation through inadequate validation of prompt lengths on a specific endpoint. When submitting requests with features payloads, the system improperly generates EngineInput directly from user-supplied tokens, bypassing checks against maximum model lengths. Notably, this issue primarily affects multimodal processors configured to skip prompt length validation. An attacker could exploit this vulnerability to submit excessively long token_ids, potentially causing a worker to fail and resulting in Denial of Service. This issue has been resolved in version 0.29.0.

Affected Version(s)

vllm 0 < 0.29.0

vllm 0.29.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rexpository
jperezdealgaba
.