vLLM 版本 0.29.0 及更早版本在预填充/解码分离式部署中,未能正确清理被拒绝推理请求的解码端元数据。远程攻击者可以提交 的请求,从而无限制地耗尽解码工作线程(decode-worker)的内存,直至该工作线程重启。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| vllm-project | vllm | ≤ 0.29.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vllm-project | vllm | 0 ~ 0.29.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet