High severity7.5NVD Advisory· Published Sep 18, 2026
CVE-2026-93592
CVE-2026-93592
Description
vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID triggers a CUDA device-side assertion that poisons the GPU context, causing all subsequent requests to fail until the process restarts.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.