vLLM 是一个用于大语言模型的推理和服务引擎。在版本 0.24.0 到 0.30.0 之间,Qwen2VLVideoBackend 和 Qwen3VLVideoBackend 类接受请求级别的 media_io_kwargs.video.max_frames 和 media_io_kwargs.video.fps 字段值,而未实施服务器端的上限限制。未经身份验证的攻击者可以向 /tokenize 端点提交这些值,导致采样器解码攻击者控制的视频输入中所选的所有帧,消耗不成比例的前端内存,并可能在调度或准入控制之前终
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vllm-project | vllm | >= 0.24.0, < 0.30.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105753 | 6.5 MEDIUM | vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reu |
| CVE-2026-105754 | 6.5 MEDIUM | vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features |
| CVE-2026-105756 | 6.5 MEDIUM | vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP de |
| CVE-2026-105757 | 6.5 MEDIUM | vLLM: Structured-output request errors escape the request boundary and terminate the share |
| CVE-2026-105759 | 5.9 MEDIUM | vLLM: Unbounded Prometheus label cardinality from attacker-controlled HTTP method tokens i |
| CVE-2026-105760 | 5.3 MEDIUM | vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion |
| CVE-2026-105755 | 4.2 MEDIUM | vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled req |
| CVE-2026-105752 | 3.1 LOW | vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache |
No comments yet