Integer Overflow Vulnerability in vLLM Inference Engine for Large Language Models
CVE-2026-73558

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-73558?

The vLLM inference engine for large language models contains an integer overflow vulnerability in the activation_kernels.cu file, specifically within the act_and_mul_kernel function. This flaw can lead to the unintended exposure of one user's inference results to another within the same inference batch. As a result, sensitive information might be leaked between different requests, potentially compromising user privacy. A patch was issued in version 0.27.0 to mitigate this issue. It is critical for users to update to the latest version to safeguard against this vulnerability.

Affected Version(s)

vllm < 0.27.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.