CVE-2026-105759
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the Rust frontend's track_http_metrics middleware records the raw HTTP method token as a Prometheus label for requests reaching registered routes. An unauthenticated attacker can send unique arbitrary method tokens to unguarded routes such as /tokenize, causing Prometheus's Family::get_or_create function to permanently create counter and histogram label sets. Those label sets increase process memory usage and enlarge the /metrics response until the service or monitoring path is exhausted. This issue is fixed in version 0.30.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| vllm-project | vllm | < 0.30.0 | affected |
Weaknesses
- CWE-400: CWE-400: Uncontrolled Resource Consumption
References
- https://github.com/vllm-project/vllm/security/advisories/GHSA-5fj9-pfhr-6j48
- https://github.com/vllm-project/vllm/pull/56058
- https://github.com/vllm-project/vllm/commit/3735c2d5f5248259482b9045c34fb7a8a3892352
- https://github.com/vllm-project/vllm/releases/tag/v0.30.0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.