Request-Level Vulnerability in vLLM Inference Engine by vLLM Project
CVE-2026-105760
5.3MEDIUM
What is CVE-2026-105760?
The vLLM inference and serving engine for large language models contains a request-level vulnerability before version 0.30.0. An attacker can exploit this flaw by using the media_io_kwargs field to select the GLMGA video backend while providing excessively large values for fps and max_frames options. This design oversight allows the creation of a pre-decode frame-index list that consumes an inordinate amount of CPU time and memory. To mitigate this issue and enhance performance, users are advised to upgrade to version 0.30.0, which implements necessary restrictions.
Affected Version(s)
vllm >= 0.23.0rc2, < 0.30.0
