vLLM 版本 0.22.0 至 0.23.0 在 Rust 实现的 HTTP 和 gRPC 前端中,未能对 进行词表边界检查,导致超出词表范围的 token ID 能够传递到 。攻击者可通过提交 大于零且包含非法(越界) 的请求,触发 CUDA 张量索引失败,从而使 进入致命状态,必须重启服务才能恢复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vllm-project | vllm | 0.22.0 ~ 0.24.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100654 | 6.5 MEDIUM | vLLM before 0.29.0 Denial of Service via out-of-range stop_token_ids |
| CVE-2026-100650 | 6.5 MEDIUM | vLLM before 0.29.0 Resource Exhaustion via Unbounded Media Materialization |
| CVE-2026-100651 | 6.5 MEDIUM | vllm before 0.29.0 Denial of Service via Decoder Prompt Length Bypass |
| CVE-2026-100653 | 6.5 MEDIUM | vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation |
| CVE-2026-100647 | 5.3 MEDIUM | vLLM before 0.29.0 CPU Exhaustion via unbounded cache_salt |
| CVE-2026-100648 | 5.3 MEDIUM | vllm before 0.29.0 Uncontrolled Resource Consumption via Audio Decoding |
| CVE-2026-100649 | 3.7 LOW | vLLM before 0.29.0 Resource Limit Bypass via Sampler Subclass |
No comments yet