PatchSiren cyber security CVE debrief
CVE-2026-100650 vllm-project CVE debrief
A remote attacker can cause the API server or batch-runner process of vLLM through 0.29.0 to allocate memory and consume outbound bandwidth proportional to an attacker-chosen body size or media item count before the request is rejected, resulting in pre-inference memory and bandwidth exhaustion (denial of service). The vulnerability exists across multiple ingress paths, including the shared media-acquisition layer, chat completions, batch speech runner, and Rust frontend POST /tokenize route. The chat and batch surfaces require an API key when one is configured; the Rust frontend /tokenize route is unauthenticated by design.
- Vendor
- vllm-project
- Product
- vllm
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-26
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-09-26
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for systems using vLLM, especially those using the chat completions, batch speech runner, or Rust frontend POST /tokenize routes, should assess their exposure and potential impact.
Why it matters
CVE-2026-100650 is a denial-of-service vulnerability in vLLM through 0.29.0, allowing a remote attacker to cause memory and bandwidth exhaustion. Defenders should prioritize verifying exposure and assessing potential impact, especially for systems using affected routes.
- Denial of service via memory and bandwidth exhaustion
- Potential disruption of API server or batch-runner process
- Need for verification of vLLM version and exposure
- Possible impact on systems using chat completions, batch speech runner, or Rust frontend POST /tokenize routes
Technical summary
vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls, allowing a remote attacker to cause the API server or batch-runner process to allocate memory and consume outbound bandwidth proportional to an attacker-chosen body size or media item count before the request is rejected, resulting in pre-inference memory and bandwidth exhaustion (denial of service).
Defensive priority
Defenders should prioritize verifying exposure of vLLM versions before 0.30.0 and assessing the potential impact on their systems, especially those using the chat completions, batch speech runner, or Rust frontend POST /tokenize routes.
Recommended defensive actions
- Verify vLLM version and assess exposure
- Implement compensating controls to limit outbound bandwidth and memory allocation
- Monitor for suspicious activity on chat completions, batch speech runner, and Rust frontend POST /tokenize routes
- Consider upgrading to vLLM version 0.30.0 or later
- Review and update incident response plans to address potential denial-of-service attacks
- Conduct a thorough risk assessment to identify potential vulnerabilities in systems using vLLM
- Engage with the vendor to obtain additional information on the vulnerability and potential mitigations
Evidence notes
The source corpus provides details on the vulnerability, including the affected versions of vLLM and the potential impact of the denial-of-service attack. However, the corpus does not provide information on code execution or data disclosure impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100650 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100650
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100650 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100650
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
PYSEC-2026-4184
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/PYSEC-2026-4184.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/vllm-before-0.29.0-resource-exhaustion-via-unbounded-media-materialization
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm/commit/752a3a504485790a2e8491cacbb35c137339ad34
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm/security/advisories/GHSA-p6g9-7v3x-m8mv
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.