CVE-2026-103241
Awaiting Analysis Awaiting Analysis - Queue

Denial of Service in vLLM due to Gemma4 Parser Flaw

Vulnerability report for CVE-2026-103241, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulDB

Description

A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 0.29.1rc0 is able to resolve this issue. This patch is called 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
vllm-project vllm to 0.26.0 (inc)
vllm-project vllm 0.29.1rc0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stack overflow vulnerability in the vLLM project's Rust-based Gemma4 unified parser. It occurs due to unbounded recursion when processing deeply nested tool-call arguments, specifically curly braces or square brackets. The parser exhausts the thread's stack, causing an immediate system crash. The flaw is in the file rust/src/parser/src/unified/gemma4.rs and affects versions up to 0.26.0.

Detection Guidance

Check if your vLLM version is below 0.29.1rc0 by running: vllm --version. Monitor for crashes when processing tool calls with deeply nested structures like curly braces or square brackets. Use logs to identify stack overflow errors in the parser.

Impact Analysis

The vulnerability can cause denial of service by crashing the system when processing maliciously crafted input with deep nesting. It may be triggered remotely through model output influenced by user prompts. Systems using affected vLLM versions could become unresponsive or require restart.

Mitigation Strategies

Upgrade vLLM to version 0.29.1rc0 or later immediately. Apply the patch commit 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9 if manual patching is preferred. Restrict input to prevent deeply nested tool calls until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103241. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart