vLLMPYSEC-2026-3999
vLLM: memory corruption
Medium5.3CVE-2026-93841 · Published Sep 18, 2026 · updated Sep 29, 2026
vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size. Attackers can submit multimodal audio requests with tokens equal to vocabulary size, causing out-of-bounds writes that corrupt concurrent requests' sampler state and alter repetition penalty behavior.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vllm PyPI | < 0.30.0 | 0.30.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity from
- the CVSS score
- Also known as
- CVE-2026-93841
- github.com/vllm-project/vllm/blob/v0.29.0/vllm/v1/worker/gpu/sample/penalties.py#L241-L255
- github.com/vllm-project/vllm/blob/v0.29.0/vllm/v1/worker/gpu/sample/penalties.py#L33-L37
- www.vulncheck.com/advisories/vllm-through-0.29.0-adjacent-request-sampler-state-corruption-via-unvalidated-prompt-token-ids
- github.com/vllm-project/vllm/pull/49081
- github.com/vllm-project/vllm
More vLLM advisories
All vLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 19 | vLLM through 0.29.0 fails to properly validate bad_words token indices against... | Medium4.3 | 0.30.0 |
| Sep 18 | vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead... | Medium5.3 | 0.29.0 |
| Sep 18 | vLLM: unauthenticated attacker could crash the engine | Unrated | 0.28.0 |
| Sep 17 | vLLM through 0.29.0 fails to properly clean up decode-side metadata for... | Unrated | 0.30.0 |
| Sep 17 | vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation | Medium6.5 | 0.28.0 |
| Sep 16 | vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions | Medium6.5 | 0.24.0 |