CVE-2026-105760
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Summary
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, a caller can use the request-level media_io_kwargs field to select the GLMGA video backend and supply large values for the fps and max_frames options without a strict work ceiling. GLMGA constructs and deduplicates an attacker-sized pre-decode frame-index list, allowing a compact request and tiny valid video to consume disproportionate CPU time and memory in the shared media-loading executor. This issue is fixed in version 0.30.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| vllm-project | vllm | >= 0.23.0rc2, < 0.30.0 | affected |
Weaknesses
- CWE-400: CWE-400: Uncontrolled Resource Consumption
References
- https://github.com/vllm-project/vllm/security/advisories/GHSA-58v5-2m8f-94pr
- https://github.com/vllm-project/vllm/pull/54935
- https://github.com/vllm-project/vllm/commit/8b6de0eb9a09ef53f20cf06bd4d17ee264b9c2a7
- https://github.com/vllm-project/vllm/releases/tag/v0.30.0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.