Remote Code Execution in vLLM by Unauthenticated Access to HTTP Metrics
CVE-2026-105759
5.9MEDIUM
What is CVE-2026-105759?
The vLLM inference and serving engine for large language models has a vulnerability in its Rust frontend, specifically in the track_http_metrics middleware. This issue allows unauthenticated attackers to send arbitrary HTTP method tokens to unguarded endpoints such as /tokenize. When these requests are processed, the Prometheus Family::get_or_create function creates new counter and histogram label sets. This not only increases memory consumption over time but can also lead to exhaustion of service endpoints, ultimately degrading the performance of the monitoring path. The issue has been resolved in version 0.30.0.
Affected Version(s)
vllm < 0.30.0
