Medium severity5.3NVD Advisory· Published Aug 13, 2026· Updated Aug 13, 2026
CVE-2026-73558
CVE-2026-73558
Description
vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.cu can cause act_and_mul_kernel to consume another batched user's input, allowing a request processed in the same inference batch to receive a partial or complete copy of another user's inference result. This issue is fixed in version 0.27.0.
Affected products
1Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.