vLLMPYSEC-2026-4000
vLLM through 0.29.0 fails to properly validate bad_words token indices against...
Medium4.3CVE-2026-93989 · Published Sep 19, 2026 · updated Sep 29, 2026
vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token indices that corrupt logits memory of concurrent requests, causing different in-flight HTTP requests to return incorrect tokens.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vllm PyPI | < 0.30.0 | 0.30.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Severity from
- the CVSS score
- Also known as
- CVE-2026-93989
- github.com/vllm-project/vllm/blob/98dff2a81d747d1dba01a47f939f48c3526d4206/vllm/sampling_params.py#L694-L753
- github.com/vllm-project/vllm/blob/98dff2a81d747d1dba01a47f939f48c3526d4206/vllm/v1/worker/gpu/sample/bad_words.py
- www.vulncheck.com/advisories/vllm-through-0.29.0-cross-request-logits-corruption-via-bad-words
- github.com/vllm-project/vllm/pull/48824
- github.com/vllm-project/vllm
More vLLM advisories
All vLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 21 | vLLM: denial of service | Unrated | 0.30.0 |
| Sep 18 | vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead... | Medium5.3 | 0.29.0 |
| Sep 18 | vLLM: memory corruption | Medium5.3 | 0.30.0 |
| Sep 18 | vLLM: unauthenticated attacker could crash the engine | Unrated | 0.28.0 |
| Sep 17 | vLLM through 0.29.0 fails to properly clean up decode-side metadata for... | Unrated | 0.30.0 |
| Sep 17 | vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation | Medium6.5 | 0.28.0 |