vLLMPYSEC-2026-4185
vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against...
Fix: upgrade to 0.24.0 or later
vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC frontends, allowing out-of-vocabulary token IDs to reach MinTokensLogitsProcessor. Attackers can submit requests with min_tokens greater than zero and out-of-vocabulary stop_token_ids to trigger CUDA tensor indexing failures that leave EngineCore in a fatal state requiring service restart.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vllm PyPI | >= 0.22.0, < 0.24.0 | 0.24.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the CVSS score
- Also known as
- CVE-2026-100652, GHSA-qff2-492f-9fm4
More vLLM advisories
All vLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 30 | vLLM: denial of service | High7.5 | 0.27.0 |
| Sep 26 | vLLM through 0.29.0 fetches and fully materializes remote or inline media... | Medium6.5 | 0.30.0 |
| Sep 21 | vLLM: denial of service | High7.5 | 0.30.0 |
| Sep 21 | vLLM: denial of service | High7.5 | 0.30.0 |
| Sep 21 | vLLM: resource exhaustion | Medium5.3 | 0.30.0 |
| Sep 21 | vLLM: attacker could allocate unbounded memory | High7.5 | 0.30.0 |