PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100650 vllm-project CVE debrief

A remote attacker can cause the API server or batch-runner process of vLLM through 0.29.0 to allocate memory and consume outbound bandwidth proportional to an attacker-chosen body size or media item count before the request is rejected, resulting in pre-inference memory and bandwidth exhaustion (denial of service). The vulnerability exists across multiple ingress paths, including the shared media-acquisition layer, chat completions, batch speech runner, and Rust frontend POST /tokenize route. The chat and batch surfaces require an API key when one is configured; the Rust frontend /tokenize route is unauthenticated by design.

Vendor
vllm-project
Product
vllm
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-26
Original CVE updated
2026-10-07
Advisory published
2026-09-26
Advisory updated
2026-10-07

Who should care

Defenders responsible for systems using vLLM, especially those using the chat completions, batch speech runner, or Rust frontend POST /tokenize routes, should assess their exposure and potential impact.

Why it matters

CVE-2026-100650 is a denial-of-service vulnerability in vLLM through 0.29.0, allowing a remote attacker to cause memory and bandwidth exhaustion. Defenders should prioritize verifying exposure and assessing potential impact, especially for systems using affected routes.

  • Denial of service via memory and bandwidth exhaustion
  • Potential disruption of API server or batch-runner process
  • Need for verification of vLLM version and exposure
  • Possible impact on systems using chat completions, batch speech runner, or Rust frontend POST /tokenize routes

Technical summary

vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls, allowing a remote attacker to cause the API server or batch-runner process to allocate memory and consume outbound bandwidth proportional to an attacker-chosen body size or media item count before the request is rejected, resulting in pre-inference memory and bandwidth exhaustion (denial of service).

Defensive priority

Defenders should prioritize verifying exposure of vLLM versions before 0.30.0 and assessing the potential impact on their systems, especially those using the chat completions, batch speech runner, or Rust frontend POST /tokenize routes.

Recommended defensive actions

  • Verify vLLM version and assess exposure
  • Implement compensating controls to limit outbound bandwidth and memory allocation
  • Monitor for suspicious activity on chat completions, batch speech runner, and Rust frontend POST /tokenize routes
  • Consider upgrading to vLLM version 0.30.0 or later
  • Review and update incident response plans to address potential denial-of-service attacks
  • Conduct a thorough risk assessment to identify potential vulnerabilities in systems using vLLM
  • Engage with the vendor to obtain additional information on the vulnerability and potential mitigations

Evidence notes

The source corpus provides details on the vulnerability, including the affected versions of vLLM and the potential impact of the denial-of-service attack. However, the corpus does not provide information on code execution or data disclosure impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100650 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100650

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100650 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100650

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • PYSEC-2026-4184

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/PYSEC-2026-4184.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/vllm-before-0.29.0-resource-exhaustion-via-unbounded-media-materialization

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vllm-project/vllm/commit/752a3a504485790a2e8491cacbb35c137339ad34

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vllm-project/vllm/security/advisories/GHSA-p6g9-7v3x-m8mv

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.