Denial of Service Vulnerability in vLLM by vLLM Project
CVE-2026-100654
7.1HIGH
What is CVE-2026-100654?
A vulnerability in vLLM versions prior to 0.29.0 allows authenticated API users to exploit the POST /v1/completions and POST /v1/chat/completions endpoints. The application improperly validates user-controlled stop_token_ids, resulting in out-of-range token ids being processed. If the min_tokens parameter is greater than 0, these out-of-range ids can trigger a CUDA indexing operation that leads to a device-side assertion failure. Consequently, this causes a 500 Internal Server Error, putting the EngineCore into a fatal state, and requires a service restart to recover. This vulnerability presents a significant denial of service risk.
Affected Version(s)
vllm 0 < 0.29.0
vllm 0.29.0
