Denial of Service Vulnerability in vLLM by vLLM Project
CVE-2026-90555
7.1HIGH
What is CVE-2026-90555?
vLLM versions prior to 0.28.0 exhibit a vulnerability where the transcription endpoint fails to properly validate audio sample rate headers. This flaw allows authenticated clients to bypass critical duration checks by submitting maliciously crafted FLAC headers with inflated sample rates. Exploiting this issue can lead to excessive memory allocation, ultimately causing the API server process to crash and affect all tenants accessing the service.
Affected Version(s)
vLLM 0 < 0.28.0
vLLM 0.28.0
