Denial of Service Vulnerability in vLLM by vLLM Project
CVE-2026-78684

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-78684?

A vulnerability in vLLM prior to version 0.27.0 allows unauthenticated attackers to exploit handling of the DeepStream GPU backend. This flaw prevents proper classification of DeepStream and bypasses pixel-limit enforcement during the decoding process. As a result, attackers can trigger a denial of service by initializing the process-wide GPU decode pool and submitting video requests that overwhelm the resource controls. This affects the system's performance, leading to partial service disruptions for concurrent users.

Affected Version(s)

vllm 0 < 0.27.0

vllm 0.27.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Charles-know
jperezdealgaba
DarkLight1337
.