Denial of Service Vulnerability in vLLM Audio Extraction Features
CVE-2026-90554

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-90554?

Versions of vLLM from 0.10.2 to 0.28.0 are susceptible to a denial of service vulnerability due to improper handling of audio extraction from video inputs. When using NanoNemotronVL models, sending a small, highly compressed video can lead the server to allocate excessive memory, significantly impacting performance and potentially causing a service outage. This issue arises because the system does not enforce limits on audio decode size or duration during audio extraction processes. The vulnerability has been addressed in vLLM version 0.28.0.

Affected Version(s)

vLLM 0.10.2 < 0.28.0

vLLM 0.28.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TobyB1702
jperezdealgaba
.