CVE-2026-105759
Received Received - Intake

Prometheus Memory Exhaustion via HTTP Method Abuse in vLLM

Vulnerability report for CVE-2026-105759, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the Rust frontend's track_http_metrics middleware records the raw HTTP method token as a Prometheus label for requests reaching registered routes. An unauthenticated attacker can send unique arbitrary method tokens to unguarded routes such as /tokenize, causing Prometheus's Family::get_or_create function to permanently create counter and histogram label sets. Those label sets increase process memory usage and enlarge the /metrics response until the service or monitoring path is exhausted. This issue is fixed in version 0.30.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
vllm-project vllm < 0.30.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

vLLM before 0.30.0 has a flaw in its Rust frontend where the track_http_metrics middleware records raw HTTP method tokens as Prometheus labels for certain routes like /tokenize. An attacker can exploit this by sending unique method tokens to these routes, causing Prometheus to create new label sets that permanently increase memory usage and enlarge the /metrics response until the service crashes or monitoring fails.

Detection Guidance

Monitor Prometheus metrics endpoint for unusual label growth in HTTP method tokens. Check for increased memory usage or enlarged /metrics responses. Use commands like 'curl http://<vllm-server>:<port>/metrics' to inspect Prometheus output for abnormal label sets.

Impact Analysis

This vulnerability can lead to denial of service by exhausting system memory and disk space due to bloated Prometheus metrics. It may also degrade performance or crash the vLLM service, disrupting LLM inference and serving operations.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it primarily impacts system resource usage and monitoring. However, if the Prometheus metrics service is disrupted due to memory exhaustion, it could indirectly impact compliance by failing to provide required logging or monitoring data for audits or incident response.

Mitigation Strategies

Upgrade vLLM to version 0.30.0 or later to fix the issue. If upgrading is not immediately possible, restrict access to unguarded routes like /tokenize and monitor Prometheus metrics for label growth.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105759. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart