Denial of Service Vulnerability in vLLM by vLLM Project
CVE-2026-90555

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-90555?

vLLM versions prior to 0.28.0 exhibit a vulnerability where the transcription endpoint fails to properly validate audio sample rate headers. This flaw allows authenticated clients to bypass critical duration checks by submitting maliciously crafted FLAC headers with inflated sample rates. Exploiting this issue can lead to excessive memory allocation, ultimately causing the API server process to crash and affect all tenants accessing the service.

Affected Version(s)

vLLM 0 < 0.28.0

vLLM 0.28.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

oran-s
jperezdealgaba
.