Denial of Service Vulnerability in vLLM by vllm-project
CVE-2026-105922
Key Information:
- Vendor
Vllm-project
- Status
- Vendor
- CVE Published:
- 6 October 2026
Badges
What is CVE-2026-105922?
A security flaw has been identified in the vLLM product of vllm-project, affecting versions up to 0.31.0. This vulnerability is rooted in the function get_token_bin_counts_and_mask located in the utils.py file of the Penalty Handler component. An attacker could exploit this issue to manipulate the process, leading to a denial of service. Furthermore, the exploit for this vulnerability has been publicly released, heightening the risk of remote exploitation. Despite an early notification to the project regarding this issue, there has yet to be any formal acknowledgment or remediation from the vendor.
Affected Version(s)
vLLM 0.1
vLLM 0.2
vLLM 0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
