CVE-2026-105757
Received Received - Intake

Engine Termination via Structured-Output Validation Bypass in vLLM

Vulnerability report for CVE-2026-105757, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

vLLM is an inference and serving engine for large language models. Prior to 0.30.0, structured-output request failures can escape request-scoped validation and reach the EngineCore fatal-error path. A per-request backend mismatch can re-raise a grammar compilation exception, padding produced by the ngram_gpu speculative-decoding mode can pass a negative token to guidance validation, and the Rust frontend can admit empty structured-output values that the Python frontend rejects, allowing ordinary constrained-generation requests to terminate the shared engine. This issue is fixed in version 0.30.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
vllm-project vllm < 0.30.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-755 The product does not handle or incorrectly handles an exceptional condition.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-248 An exception is thrown from a function, but it is not caught.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

vLLM versions before 0.30.0 have a flaw where structured-output request failures bypass request validation and reach the EngineCore fatal-error path. This can happen due to backend mismatches, negative tokens from ngram_gpu speculative decoding, or empty structured-output values. These issues allow constrained-generation requests to crash the shared engine.

Detection Guidance

Detection requires checking the vLLM version in use. Run 'pip show vllm' or 'vllm --version' to verify if the installed version is below 0.30.0. If so, the system is vulnerable.

Impact Analysis

This vulnerability can cause service disruption by terminating the shared engine during normal operations. If exploited, it may lead to denial of service for all users relying on the affected vLLM instance.

Compliance Impact

The vulnerability in vLLM could lead to service disruption by terminating the shared engine, potentially causing downtime or data processing interruptions. This may impact compliance with GDPR or HIPAA by failing to ensure availability of systems processing personal or health data.

Mitigation Strategies

Upgrade vLLM to version 0.30.0 or later immediately. Use 'pip install --upgrade vllm' or update via your package manager. Restart services using vLLM to apply changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105757. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart