Denial of Service Vulnerability in vLLM by vLLM Project
CVE-2026-100652
8.2HIGH
What is CVE-2026-100652?
Versions 0.22.0 through 0.23.0 of vLLM contain a vulnerability in their handling of stop_token_ids, failing to validate these IDs against predefined vocabulary bounds. This oversight permits attackers to leverage requests with out-of-vocabulary token IDs and a min_tokens value greater than zero, leading to CUDA tensor indexing failures. Such failures can place EngineCore into a critical state, necessitating a service restart to recover functionality. This vulnerability poses significant risks for service availability in applications utilizing vLLM for HTTP and gRPC communications.
Affected Version(s)
vllm 0.22.0 < 0.24.0
vllm 0.24.0
