CVE-2026-54234High· 7.5▾ TwilightA flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for Large Language Models (LLMs). A remote attacker can exploit this vulnerability by sending a specially crafted multi-request speculative decod…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
0.3% → 0.6%
Last analysed / modified upstream
A flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for Large Language Models (LLMs). A remote attacker can exploit this vulnerability by sending a specially crafted multi-request speculative decoding workload through public gRPC Generate and Abort endpoints. This malformed workload can cause the rejection sampler to produce an out-of-vocabulary token, which then crashes the engine worker. This leads to a service-wide Denial of Service (DoS) for all clients until the worker is restarted.
vllm: vLLM: Denial of Service via malformed speculative decoding workload — rated Important by Red Hat. Released 2026-07-06, updated 2026-09-24.
Affected:
Fixed:
No fix planned:
Not affected:
For more information visit https://access.redhat.com/errata/RHSA-2026:61627 https://access.redhat.com/errata/RHSA-2026:61627 For more information visit https://access.redhat.com/errata/RHSA-2026:61629 https://access.redhat.com/errata/RHSA-2026:61629 For more information visit https://access.redhat.com/errata/RHSA-2026:60363 https://access.redhat.com/errata/RHSA-2026:60363
Workarounds / mitigations:
Affected packages:
vllm >= 0.17.1, < 0.24.0Patched in:
vllm 0.24.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57585High· 7.5msgpack: MessagePack for Python: Denial of Service via Unpacker reuse after error (CVE-2026-57585)
CVE-2026-55574High· 7.5vllm: vLLM: Denial of Service via adversarial regular expression in structured outputs API (CVE-2026-55574)
CVE-2026-5241High· 7.7python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting (CVE-2026-5241)
CVE-2026-45804High· 7.5diffusers: Diffusers: Arbitrary code execution due to trust_remote_code guard bypass (CVE-2026-45804)
CVE-2026-41523High· 7.5vllm: vLLM: Arbitrary code execution via malicious HuggingFace model (CVE-2026-41523)
CVE-2026-96546Low· 2.5A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader