Vulnerability PYSEC-2026-4185
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
10 days ago
September 26, 2026 at 02:16 PM UTC
No summary available
0.22.0 - 0.23.0
0.22.0 - 0.23.0
Details
vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC frontends, allowing out-of-vocabulary token IDs to reach MinTokensLogitsProcessor. Attackers can submit requests with min_tokens greater than zero and out-of-vocabulary stop_token_ids to trigger CUDA tensor indexing failures that leave EngineCore in a fatal state requiring service restart.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
1 day ago
vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core
0.0.1 - 0.27.1 GHSA-ph3r-5jfg-f84f
0.0.1 - 0.27.1 GHSA-ph3r-5jfg-f84f
Low Risk
1 day ago
vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle
0.0.1 - 0.29.0 GHSA-935w-9g4m-p28p
0.0.1 - 0.29.0 GHSA-935w-9g4m-p28p
Medium Risk
1 day ago
vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach
0.24.0 - 0.29.0 GHSA-x6mc-67gf-chw4
0.24.0 - 0.29.0 GHSA-x6mc-67gf-chw4
Medium Risk
1 day ago
vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion
0.23.0 - 0.29.0 GHSA-58v5-2m8f-94pr
0.23.0 - 0.29.0 GHSA-58v5-2m8f-94pr
Medium Risk
1 day ago
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features
0.0.1 - 0.29.0 GHSA-ph72-cqr5-qpp7
0.0.1 - 0.29.0 GHSA-ph72-cqr5-qpp7
Impacted packages
Timeline
Published
10 days ago
September 26, 2026 at 02:16 PM UTC
Fixed (0.24.0)
3 months ago
June 30, 2026 at 01:18 AM UTC
Last Modified
3 hours ago
October 07, 2026 at 10:00 AM UTC