VYPR
Medium severity5.9NVD Advisory· Published Sep 26, 2026

CVE-2026-100652

CVE-2026-100652

Description

vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC frontends, allowing out-of-vocabulary token IDs to reach MinTokensLogitsProcessor. Attackers can submit requests with min_tokens greater than zero and out-of-vocabulary stop_token_ids to trigger CUDA tensor indexing failures that leave EngineCore in a fatal state requiring service restart.

Affected products

1
  • Vllm/Vllmllm-create
    Range: 0.22.0 - 0.23.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.