PatchSiren cyber security CVE debrief
CVE-2026-105758 vllm-project CVE debrief
The vLLM inference and serving engine for large language models, versions from 0.24.0 until 0.30.0, contains a vulnerability in the Qwen2VLVideoBackend and Qwen3VLVideoBackend classes. These classes accept and use request-level values for video.max_frames and video.fps without enforcing server-side limits. An unauthenticated user can submit these values to the /tokenize endpoint, causing the video sampler to decode every frame from attacker-controlled video input. This can lead to disproportionate frontend memory consumption and potentially terminate the API process before scheduling or admission control. The Rust frontend is not affected as it rejects the media_io_kwargs field. This issue is fixed in version 0.30.0.
- Vendor
- vllm-project
- Product
- vllm
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for systems using vLLM, especially those exposed to untrusted input, should assess and mitigate this vulnerability. They should prioritize patching or mitigating CVE-2026-105758 due to potential for API process termination and excessive memory consumption from uncontrolled video frame processing. Defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Why it matters
Defenders should prioritize patching or mitigating CVE-2026-105758 due to potential for API process termination and excessive memory consumption from uncontrolled video frame processing.
- Potential API process termination
- Excessive frontend memory consumption
- Uncontrolled video frame processing
Technical summary
The Qwen2VLVideoBackend and Qwen3VLVideoBackend classes in vLLM accept request-level values for video.max_frames and video.fps without server-side limits, allowing an unauthenticated user to cause excessive memory consumption and potentially terminate the API process by decoding every frame selected from attacker-controlled video input. This issue is fixed in version 0.30.0 and can be mitigated by restricting access to the /tokenize endpoint and monitoring for unusual activity. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity.
Defensive priority
Defenders should prioritize patching or mitigating this vulnerability, especially for systems exposed to untrusted input.
Recommended defensive actions
- Patch to version 0.30.0 or later
- Restrict access to the /tokenize endpoint
- Monitor for unusual activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details about the vulnerability, its impact, and the fix in version 0.30.0. The vulnerability affects vLLM versions from 0.24.0 until 0.30.0, specifically the Qwen2VLVideoBackend and Qwen3VLVideoBackend classes. An unauthenticated user can submit request-level values to the /tokenize endpoint, causing the video sampler to decode every frame from attacker-controlled video input. This can lead to disproportionate frontend memory consumption and potentially terminate the API process before. The Rust
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105758 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105758
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105758 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105758
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_f
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105758.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm/security/advisories/GHSA-x6mc-67gf-chw4
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm/pull/56729
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm/commit/ea723c81c3ea26425cb69503a5d5e90822a04a45
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm/releases/tag/v0.30.0
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.