vLLM 0.28.0 之前的版本在语音转录端点(transcription endpoint)中未校验音频采样率(sample rate)头部信息,使得已认证的客户端能够绕过时长(duration)检查。攻击者可以提交伪造的 FLAC 头部信息,其中采样率被故意夸大,从而触发过度的内存分配,导致 API 服务器进程崩溃,影响所有租户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vllm-project | vLLM | 0 ~ 0.28.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90553 | 7.8 HIGH | vLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processor |
| CVE-2026-90554 | 6.2 MEDIUM | vLLM before 0.28.0 Denial of Service via audio extraction |
No comments yet