Vulnerability PYSEC-2026-3996
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
11 days ago
September 17, 2026 at 11:18 PM UTC
No summary available
0.0.1 - 0.29.0
0.0.1 - 0.29.0
Details
vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 to exhaust decode-worker memory without bound until the worker restarts.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
9 days ago
No summary available
0.0.1 - 0.29.0 PYSEC-2026-4000
0.0.1 - 0.29.0 PYSEC-2026-4000
Medium Risk
10 days ago
No summary available
0.0.1 - 0.28.0 PYSEC-2026-3998
0.0.1 - 0.28.0 PYSEC-2026-3998
Medium Risk
10 days ago
No summary available
0.0.1 - 0.29.0 PYSEC-2026-3999
0.0.1 - 0.29.0 PYSEC-2026-3999
Unknown
10 days ago
No summary available
0.0.1 - 0.27.1 PYSEC-2026-3997
0.0.1 - 0.27.1 PYSEC-2026-3997
Medium Risk
11 days ago
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
0.0.1 - 0.27.1 GHSA-8pw2-6jv3-mj5j
0.0.1 - 0.27.1 GHSA-8pw2-6jv3-mj5j
Impacted packages
Timeline
Published
11 days ago
September 17, 2026 at 11:18 PM UTC
Fixed (0.30.0)
7 days ago
September 22, 2026 at 05:23 AM UTC
Last Modified
2 hours ago
September 29, 2026 at 09:00 AM UTC