Denial of Service Vulnerability in vLLM by vLLM Project
CVE-2026-100652

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100652?

Versions 0.22.0 through 0.23.0 of vLLM contain a vulnerability in their handling of stop_token_ids, failing to validate these IDs against predefined vocabulary bounds. This oversight permits attackers to leverage requests with out-of-vocabulary token IDs and a min_tokens value greater than zero, leading to CUDA tensor indexing failures. Such failures can place EngineCore into a critical state, necessitating a service restart to recover functionality. This vulnerability poses significant risks for service availability in applications utilizing vLLM for HTTP and gRPC communications.

Affected Version(s)

vllm 0.22.0 < 0.24.0

vllm 0.24.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rexpository
jperezdealgaba
.