Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105758— vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach

Quick assessment

Affected
vllm-project vllm
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

vLLM 是一个用于大语言模型的推理和服务引擎。在版本 0.24.0 到 0.30.0 之间,Qwen2VLVideoBackend 和 Qwen3VLVideoBackend 类接受请求级别的 media_io_kwargs.video.max_frames 和 media_io_kwargs.video.fps 字段值,而未实施服务器端的上限限制。未经身份验证的攻击者可以向 /tokenize 端点提交这些值,导致采样器解码攻击者控制的视频输入中所选的所有帧,消耗不成比例的前端内存,并可能在调度或准入控制之前终

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105758

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach
Source: CVE Program / CVE List V5
Vulnerability Description
vLLM is an inference and serving engine for large language models. From 0.24.0 until 0.30.0, the Qwen2VLVideoBackend and Qwen3VLVideoBackend classes accept request-level values for the media_io_kwargs.video.max_frames and media_io_kwargs.video.fps fields without enforcing server-side ceilings. An unauthenticated caller can submit these values to the /tokenize endpoint, causing the sampler to decode every frame selected from attacker-controlled video input, consume disproportionate frontend memory, and potentially terminate the API process before scheduling or admission control. The Rust frontend is not affected because it rejects the media_io_kwargs field. This issue is fixed in version 0.30.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
vllm-project vllm >= 0.24.0, < 0.30.0 -

II. Public POCs for CVE-2026-105758

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105758

请登录查看更多情报信息。

Other References for CVE-2026-105758 (4)

Same Patch Batch · vllm-project · 2026-10-05 · 9 CVEs total

CVE-2026-105753 6.5 MEDIUM vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reu
CVE-2026-105754 6.5 MEDIUM vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features
CVE-2026-105756 6.5 MEDIUM vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP de
CVE-2026-105757 6.5 MEDIUM vLLM: Structured-output request errors escape the request boundary and terminate the share
CVE-2026-105759 5.9 MEDIUM vLLM: Unbounded Prometheus label cardinality from attacker-controlled HTTP method tokens i
CVE-2026-105760 5.3 MEDIUM vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion
CVE-2026-105755 4.2 MEDIUM vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled req
CVE-2026-105752 3.1 LOW vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache

IV. Related Vulnerabilities

V. Comments for CVE-2026-105758

No comments yet


Leave a comment