Skip to content
vLLMPYSEC-2026-4000

vLLM through 0.29.0 fails to properly validate bad_words token indices against...

Medium4.3CVE-2026-93989 · Published Sep 19, 2026 · updated Sep 29, 2026

vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token indices that corrupt logits memory of concurrent requests, causing different in-flight HTTP requests to return incorrect tokens.

Source advisory

Affected versions

PackageAffectedFixed in
vllm
PyPI
< 0.30.00.30.0
Details and references

More vLLM advisories

All vLLM
Advisory
vLLM: denial of service
UnratedSep 21
vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead...
Medium5.3Sep 18
vLLM: memory corruption
Medium5.3Sep 18
vLLM: unauthenticated attacker could crash the engine
UnratedSep 18
vLLM through 0.29.0 fails to properly clean up decode-side metadata for...
UnratedSep 17
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
Medium6.5Sep 17

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.