{"data":{"id":"1395ba45-f52b-4be1-adb6-4dca4ca627be","title":"CVE-2026-100654: vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/cha","summary":"vLLM before version 0.29.0 has a vulnerability where it accepts user-controlled stop_token_ids (values that tell the AI when to stop generating text) on two endpoints without properly validating them. If a user sends an invalid token ID that doesn't exist in the model's vocabulary, it crashes the AI engine with a CUDA error (a low-level graphics processor operation), causing the service to stop working until it restarts, which is a denial of service attack (making a service unavailable).","solution":"Update to vLLM 0.29.0 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100654","publishedAt":"2026-09-26T14:16:48.100Z","cveId":"CVE-2026-100654","cweIds":["CWE-129"],"cvssScore":"6.5","cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-26T14:16:48.100Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}