Denial of Service Vulnerability in vLLM by vLLM Project
CVE-2026-100654

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100654?

A vulnerability in vLLM versions prior to 0.29.0 allows authenticated API users to exploit the POST /v1/completions and POST /v1/chat/completions endpoints. The application improperly validates user-controlled stop_token_ids, resulting in out-of-range token ids being processed. If the min_tokens parameter is greater than 0, these out-of-range ids can trigger a CUDA indexing operation that leads to a device-side assertion failure. Consequently, this causes a 500 Internal Server Error, putting the EngineCore into a fatal state, and requires a service restart to recover. This vulnerability presents a significant denial of service risk.

Affected Version(s)

vllm 0 < 0.29.0

vllm 0.29.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

passer12
jperezdealgaba
QwertyJack
.