VYPR
Medium severity6.5NVD Advisory· Published Sep 12, 2026

CVE-2026-90555

CVE-2026-90555

Description

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Vllm/Vllminferred2 versions
    <0.28.0+ 1 more
    • (no CPE)range: <0.28.0
    • (no CPE)range: <0.28.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.