vLLMPYSEC-2026-3998
vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead...
Medium5.3CVE-2026-93840 · Published Sep 18, 2026 · updated Sep 29, 2026
vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). Attackers can supply token IDs above the output vocabulary that pass validation, causing LogitBiasState to corrupt GPU logits state and allow concurrent requests to sample tokens outside their allowlists.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vllm PyPI | < 0.29.0 | 0.29.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity from
- the CVSS score
- Also known as
- CVE-2026-93840
- github.com/vllm-project/vllm/blob/v0.28.0/vllm/sampling_params.py#L881-L903
- github.com/vllm-project/vllm/blob/v0.28.0/vllm/v1/worker/gpu/sample/logit_bias.py#L179-L191
- www.vulncheck.com/advisories/vllm-before-0.29.0-cross-request-logits-corruption-via-allowed-token-ids
- github.com/vllm-project/vllm/commit/5b0e5b69ac1a3884a6479c9537789c95263cc804
- github.com/vllm-project/vllm/pull/49080
- github.com/vllm-project/vllm
More vLLM advisories
All vLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 19 | vLLM through 0.29.0 fails to properly validate bad_words token indices against... | Medium4.3 | 0.30.0 |
| Sep 18 | vLLM: memory corruption | Medium5.3 | 0.30.0 |
| Sep 18 | vLLM: unauthenticated attacker could crash the engine | Unrated | 0.28.0 |
| Sep 17 | vLLM through 0.29.0 fails to properly clean up decode-side metadata for... | Unrated | 0.30.0 |
| Sep 17 | vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation | Medium6.5 | 0.28.0 |
| Sep 16 | vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions | Medium6.5 | 0.24.0 |