CVE-2026-105758
Received Received - Intake

Memory Exhaustion in vLLM Video Processing

Vulnerability report for CVE-2026-105758, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

vLLM is an inference and serving engine for large language models. From 0.24.0 until 0.30.0, the Qwen2VLVideoBackend and Qwen3VLVideoBackend classes accept request-level values for the media_io_kwargs.video.max_frames and media_io_kwargs.video.fps fields without enforcing server-side ceilings. An unauthenticated caller can submit these values to the /tokenize endpoint, causing the sampler to decode every frame selected from attacker-controlled video input, consume disproportionate frontend memory, and potentially terminate the API process before scheduling or admission control. The Rust frontend is not affected because it rejects the media_io_kwargs field. This issue is fixed in version 0.30.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
vllm-project vllm >= 0.24.0, < 0.30.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in vLLM versions 0.24.0 to 0.30.0 allows unauthenticated users to submit requests with high media_io_kwargs.video.max_frames and media_io_kwargs.video.fps values to the /tokenize endpoint. This causes excessive frame decoding from attacker-controlled video input, leading to high memory consumption and potential API process termination.

Detection Guidance

This vulnerability can be detected by checking the vLLM version in use. If your system runs versions between 0.24.0 and 0.30.0, it is potentially vulnerable. Inspect the installed package with commands like pip show vllm or checking version files in the deployment directory.

Impact Analysis

An attacker could exploit this to consume excessive server memory, causing service disruption or crashes. This may lead to downtime, degraded performance, or denial of service for legitimate users accessing the vLLM API.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling denial-of-service attacks that disrupt service availability. Uncontrolled resource consumption may lead to service unavailability, which could violate availability requirements in GDPR Article 32 and HIPAA Security Rule Section 164.308(a)(7).

Mitigation Strategies

Upgrade vLLM to version 0.30.0 or later immediately. If upgrading is not possible, restrict access to the /tokenize endpoint to prevent unauthenticated calls. Monitor API processes for unexpected memory consumption or crashes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105758. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart