CyberRota Analysis
AI-GeneratedVersions of vLLM prior to 0.28.0 are vulnerable due to inadequate validation of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to submit negative token IDs. This can lead to a denial of service by crashing the engine, as the GPU context becomes poisoned and requires a process restart to recover. Organizations using affected versions should prioritize patching to mitigate this high-severity vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID triggers a CUDA device-side assertion that poisons the GPU context, causing all subsequent requests to fail until the process restarts.
Related CVEs
Other vulnerabilities affecting the same vendor(s)