Structured Output Validation Flaw in vLLM by vLLM Project
CVE-2026-105757
6.5MEDIUM
What is CVE-2026-105757?
The issue in vLLM, an inference engine for large language models, arises from structured-output request failures that evade request-scoped validation, allowing potential disruptions. Specifically, a mismatch in per-request backend handling could re-trigger a grammar compilation exception, while padding introduced during ngram_gpu speculative-decoding may erroneously pass a negative token for guidance validation. Additionally, the Rust frontend may accept empty structured-output values that the Python frontend typically disallows, resulting in ordinary constrained-generation requests potentially terminating the shared engine. This issue has been addressed in vLLM version 0.30.0.
Affected Version(s)
vllm < 0.30.0
