Low severity3.7NVD Advisory· Published Sep 18, 2026
CVE-2026-93840
CVE-2026-93840
Description
vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). Attackers can supply token IDs above the output vocabulary that pass validation, causing LogitBiasState to corrupt GPU logits state and allow concurrent requests to sample tokens outside their allowlists.
Patches
Vulnerability mechanics
References
5- github.com/vllm-project/vllm/blob/v0.28.0/vllm/sampling_params.pynvd
- github.com/vllm-project/vllm/blob/v0.28.0/vllm/v1/worker/gpu/sample/logit_bias.pynvd
- github.com/vllm-project/vllm/commit/5b0e5b69ac1a3884a6479c9537789c95263cc804nvd
- github.com/vllm-project/vllm/pull/49080nvd
- www.vulncheck.com/advisories/vllm-before-0.29.0-cross-request-logits-corruption-via-allowed-token-idsnvd
News mentions
0No linked articles in our index yet.