PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105758 vllm-project CVE debrief

The vLLM inference and serving engine for large language models, versions from 0.24.0 until 0.30.0, contains a vulnerability in the Qwen2VLVideoBackend and Qwen3VLVideoBackend classes. These classes accept and use request-level values for video.max_frames and video.fps without enforcing server-side limits. An unauthenticated user can submit these values to the /tokenize endpoint, causing the video sampler to decode every frame from attacker-controlled video input. This can lead to disproportionate frontend memory consumption and potentially terminate the API process before scheduling or admission control. The Rust frontend is not affected as it rejects the media_io_kwargs field. This issue is fixed in version 0.30.0.

Vendor
vllm-project
Product
vllm
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-08
Advisory published
2026-10-05
Advisory updated
2026-10-08

Who should care

Defenders responsible for systems using vLLM, especially those exposed to untrusted input, should assess and mitigate this vulnerability. They should prioritize patching or mitigating CVE-2026-105758 due to potential for API process termination and excessive memory consumption from uncontrolled video frame processing. Defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Why it matters

Defenders should prioritize patching or mitigating CVE-2026-105758 due to potential for API process termination and excessive memory consumption from uncontrolled video frame processing.

  • Potential API process termination
  • Excessive frontend memory consumption
  • Uncontrolled video frame processing

Technical summary

The Qwen2VLVideoBackend and Qwen3VLVideoBackend classes in vLLM accept request-level values for video.max_frames and video.fps without server-side limits, allowing an unauthenticated user to cause excessive memory consumption and potentially terminate the API process by decoding every frame selected from attacker-controlled video input. This issue is fixed in version 0.30.0 and can be mitigated by restricting access to the /tokenize endpoint and monitoring for unusual activity. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity.

Defensive priority

Defenders should prioritize patching or mitigating this vulnerability, especially for systems exposed to untrusted input.

Recommended defensive actions

  • Patch to version 0.30.0 or later
  • Restrict access to the /tokenize endpoint
  • Monitor for unusual activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details about the vulnerability, its impact, and the fix in version 0.30.0. The vulnerability affects vLLM versions from 0.24.0 until 0.30.0, specifically the Qwen2VLVideoBackend and Qwen3VLVideoBackend classes. An unauthenticated user can submit request-level values to the /tokenize endpoint, causing the video sampler to decode every frame from attacker-controlled video input. This can lead to disproportionate frontend memory consumption and potentially terminate the API process before. The Rust

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105758 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105758

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105758 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105758

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_f

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105758.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vllm-project/vllm/security/advisories/GHSA-x6mc-67gf-chw4

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vllm-project/vllm/pull/56729

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vllm-project/vllm/commit/ea723c81c3ea26425cb69503a5d5e90822a04a45

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vllm-project/vllm/releases/tag/v0.30.0

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.