OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-100651

MEDIUM · CVSS 6.5 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

vLLM versions prior to 0.29.0 are vulnerable due to a lack of validation for prompt lengths on the disaggregated serving endpoint, allowing attackers to submit excessively long token_ids. This can lead to worker failures and result in a denial of service for the affected models. Organizations utilizing vLLM for multimodal processing should prioritize upgrading to version 0.29.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100651
Severity
MEDIUM
CVSS
6.5
EPSS
0.31%

Original NVD Description

vLLM before 0.29.0 fails to enforce decoder prompt-length validation on the disaggregated serving endpoint /inference/v1/generate. When the request contains a 'features' (multimodal) payload, vllm/entrypoints/serve/disagg/serving.py builds a multimodal EngineInput directly from the caller-supplied token_ids, and GenerateRequest.token_ids (vllm/entrypoints/serve/disagg/protocol.py) is not checked against model_config.max_model_len. For multimodal processors that report skip_prompt_length_check=True (for example Nemotron Parse, Whisper, and FireRedLID), InputProcessor._validate_prompt_len() returns immediately for both encoder and decoder prompts, so an overlong prompt becomes an EngineCoreRequest and reaches the worker input-batch copy into a fixed max_model_len-wide NumPy row. A client able to reach the endpoint on an affected model configuration can therefore submit an overlong token_ids list to trigger a worker failure and denial of service. Fixed in 0.29.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)