Vulnerability PYSEC-2026-3998

Medium Risk
MEDIUM RISK
CVSS Score: 5.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
10 days ago
September 18, 2026 at 08:17 PM UTC
No summary available
0.0.1 - 0.28.0
0.0.1 - 0.28.0

Details

vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). Attackers can supply token IDs above the output vocabulary that pass validation, causing LogitBiasState to corrupt GPU logits state and allow concurrent requests to sample tokens outside their allowlists.

Impacted packages

Timeline

Published
10 days ago
September 18, 2026 at 08:17 PM UTC
Fixed (0.29.0)
20 days ago
September 09, 2026 at 08:58 AM UTC
Last Modified
2 hours ago
September 29, 2026 at 09:00 AM UTC