Denial of Service Vulnerability in vLLM Audio Extraction Features
CVE-2026-90554
6.9MEDIUM
What is CVE-2026-90554?
Versions of vLLM from 0.10.2 to 0.28.0 are susceptible to a denial of service vulnerability due to improper handling of audio extraction from video inputs. When using NanoNemotronVL models, sending a small, highly compressed video can lead the server to allocate excessive memory, significantly impacting performance and potentially causing a service outage. This issue arises because the system does not enforce limits on audio decode size or duration during audio extraction processes. The vulnerability has been addressed in vLLM version 0.28.0.
Affected Version(s)
vLLM 0.10.2 < 0.28.0
vLLM 0.28.0
