AI and data stack advisories

Severe, 6 weeks2973Projects319

2973 severe, 6 weeks · 319 projects

vLLMPYSEC-2026-4185

vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against...

vLLM

CVE-2026-100652 · Published Sep 26, 2026 · updated Oct 7, 2026

High7.5
Fix: upgrade to 0.24.0 or later
Source advisory

vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC frontends, allowing out-of-vocabulary token IDs to reach MinTokensLogitsProcessor. Attackers can submit requests with min_tokens greater than zero and out-of-vocabulary stop_token_ids to trigger CUDA tensor indexing failures that leave EngineCore in a fatal state requiring service restart.

Affected versions

PackageAffectedFixed in
vllm
PyPI
>= 0.22.0, < 0.24.00.24.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
the CVSS score
Also known as
CVE-2026-100652, GHSA-qff2-492f-9fm4

More vLLM advisories

All vLLM
Advisory
vLLM: denial of service
High7.5Sep 30
vLLM through 0.29.0 fetches and fully materializes remote or inline media...
Medium6.5Sep 26
vLLM: denial of service
High7.5Sep 21
vLLM: denial of service
High7.5Sep 21
vLLM: resource exhaustion
Medium5.3Sep 21
vLLM: attacker could allocate unbounded memory
High7.5Sep 21