在 0.29.0 及之前版本的 vLLM 中, 未能正确验证 中的词元索引是否与模型的生成输出宽度(output width)匹配。攻击者可以提供超出范围的词元索引,从而破坏并发请求的 logits 内存,导致正在处理中的不同 HTTP 请求返回错误的词元。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vllm-project | vllm | 0 ~ 0.29.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet