---
id: CVE-2026-90555
title: >-
  vLLM versions before 0.28.0 fail to validate audio sample rate headers in the
  transcription endpoint, allowing authenticated clients to bypass duration
  checks
summary: >-
  vLLM versions before 0.28.0 fail to validate audio sample rate headers in the
  transcription endpoint, allowing authenticated clients to bypass duration
  checks. Attackers can submit forged FLAC headers with inflated sample rates to
  trigge…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-409
  - CWE-770
vendor: vllm
product: vllm
affected:
  - vllm < 0.28.0
patched:
  - vllm 0.28.0
published: '2026-09-12'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T17:31:06.907'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90555'
references:
  - url: >-
      https://github.com/vllm-project/vllm/security/advisories/GHSA-99f2-hwrc-gvq8
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/vllm-before-0.28.0-denial-of-service-via-audio-header
    label: disclosure@vulncheck.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90555.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-90555'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532566'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-90555'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90555'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.0052
epssPercentile: 0.41732
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T16:00:25.914795Z'
ingestedAt: '2026-09-14T15:23:07.479Z'
---

## Overview

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.

## Affected

- `vllm < 0.28.0`

## Remediation

Upgrade past the affected range:

- `vllm 0.28.0`

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90555.json)
