Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 26 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC frontends, allowing out-of-vocabulary token IDs to reach MinTokensLogitsProcessor. Attackers can submit requests with min_tokens greater than zero and out-of-vocabulary stop_token_ids to trigger CUDA tensor indexing failures that leave EngineCore in a fatal state requiring service restart. | |
| Title | vLLM 0.22.0 through 0.23.0 Denial of Service via stop_token_ids | |
| First Time appeared |
Vllm
Vllm vllm |
|
| Weaknesses | CWE-20 | |
| CPEs | cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vllm
Vllm vllm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-26T13:23:21.865Z
Reserved: 2026-09-26T02:33:07.899Z
Link: CVE-2026-100652
No data.
Status : Received
Published: 2026-09-26T14:16:47.810
Modified: 2026-09-26T14:16:47.810
Link: CVE-2026-100652
No data.
OpenCVE Enrichment
Updated: 2026-09-26T16:00:09Z