Request-Level Vulnerability in vLLM Inference Engine by vLLM Project
CVE-2026-105760

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105760?

The vLLM inference and serving engine for large language models contains a request-level vulnerability before version 0.30.0. An attacker can exploit this flaw by using the media_io_kwargs field to select the GLMGA video backend while providing excessively large values for fps and max_frames options. This design oversight allows the creation of a pre-decode frame-index list that consumes an inordinate amount of CPU time and memory. To mitigate this issue and enhance performance, users are advised to upgrade to version 0.30.0, which implements necessary restrictions.

Affected Version(s)

vllm >= 0.23.0rc2, < 0.30.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.