Remote Code Execution in vLLM by Unauthenticated Access to HTTP Metrics
CVE-2026-105759

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105759?

The vLLM inference and serving engine for large language models has a vulnerability in its Rust frontend, specifically in the track_http_metrics middleware. This issue allows unauthenticated attackers to send arbitrary HTTP method tokens to unguarded endpoints such as /tokenize. When these requests are processed, the Prometheus Family::get_or_create function creates new counter and histogram label sets. This not only increases memory consumption over time but can also lead to exhaustion of service endpoints, ultimately degrading the performance of the monitoring path. The issue has been resolved in version 0.30.0.

Affected Version(s)

vllm < 0.30.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.