Structured Output Validation Flaw in vLLM by vLLM Project
CVE-2026-105757

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105757?

The issue in vLLM, an inference engine for large language models, arises from structured-output request failures that evade request-scoped validation, allowing potential disruptions. Specifically, a mismatch in per-request backend handling could re-trigger a grammar compilation exception, while padding introduced during ngram_gpu speculative-decoding may erroneously pass a negative token for guidance validation. Additionally, the Rust frontend may accept empty structured-output values that the Python frontend typically disallows, resulting in ordinary constrained-generation requests potentially terminating the shared engine. This issue has been addressed in vLLM version 0.30.0.

Affected Version(s)

vllm < 0.30.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.