---
id: CVE-2026-100649
title: >-
  vLLM before 0.29.0 contains a resource-limit bypass vulnerability in
  PyNvVideoCodec decoder allocation where sampler subclass shadowing allows
  independent counter increments
summary: >-
  vLLM before 0.29.0 contains a resource-limit bypass vulnerability in
  PyNvVideoCodec decoder allocation where sampler subclass shadowing allows
  independent counter increments. Unauthenticated attackers can select different
  sampler subclas…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-770
vendor: vllm-project
product: vllm
affected:
  - vllm < 0.29.0
published: '2026-09-26'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T14:16:47.380'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100649'
references:
  - url: >-
      https://github.com/vllm-project/vllm/security/advisories/GHSA-j682-9xp5-rrf3
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/vllm-before-0.29.0-resource-limit-bypass-via-sampler-subclass
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-26T13:33:20.920Z'
---

## Overview

vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler subclass shadowing allows independent counter increments. Unauthenticated attackers can select different sampler subclasses in video requests to exceed configured decoder limits and exhaust unaccounted GPU memory.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
