Vulnerability PYSEC-2026-4003

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 month ago
August 25, 2026 at 12:16 PM UTC
No summary available
0.0.1 - 0.26.0
0.0.1 - 0.26.0

Details

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.

Impacted packages

Timeline

Published
1 month ago
August 25, 2026 at 12:16 PM UTC
Fixed (0.27.0)
1 month ago
August 10, 2026 at 09:31 PM UTC
Last Modified
5 hours ago
September 30, 2026 at 09:15 AM UTC