{"id":"CVE-2026-105757","title":"vLLM is an inference and serving engine for large language models","summary":"vLLM is an inference and serving engine for large language models. Prior to 0.30.0, structured-output request failures can escape request-scoped validation and reach the EngineCore fatal-error path. A per-request backend mismatch can re-…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-20","CWE-248","CWE-755"],"vendor":"vllm-project","product":"vllm","affected":["vllm < 0.30.0"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T23:17:02.467","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105757","references":[{"url":"https://github.com/vllm-project/vllm/commit/c55e15a44ec4127832d4a86928a356fdd9e68dbd","label":"security-advisories@github.com"},{"url":"https://github.com/vllm-project/vllm/pull/51450","label":"security-advisories@github.com"},{"url":"https://github.com/vllm-project/vllm/releases/tag/v0.30.0","label":"security-advisories@github.com"},{"url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-85xf-c7hm-whqw","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-85xf-c7hm-whqw"}],"tags":["nvd","cve.org","ghsa","pip"],"ingestedAt":"2026-10-05T23:36:21.157Z","aliases":["GHSA-85xf-c7hm-whqw"],"ecosystem":"pip","patched":["vllm 0.30.0"],"slug":"CVE-2026-105757","body":"## Overview\n\nvLLM is an inference and serving engine for large language models. Prior to 0.30.0, structured-output request failures can escape request-scoped validation and reach the EngineCore fatal-error path. A per-request backend mismatch can re-raise a grammar compilation exception, padding produced by the ngram_gpu speculative-decoding mode can pass a negative token to guidance validation, and the Rust frontend can admit empty structured-output values that the Python frontend rejects, allowing ordinary constrained-generation requests to terminate the shared engine. This issue is fixed in version 0.30.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-105757)\n\nAffected packages:\n\n- `vllm < 0.30.0`\n\nPatched in:\n\n- `vllm 0.30.0`\n\nSource: https://github.com/advisories/GHSA-85xf-c7hm-whqw","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}