{"data":{"id":"3db0173d-9a93-44dc-bf7c-daa91b146177","title":"CVE-2026-100650: vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls","summary":"vLLM versions up to 0.29.0 have a security flaw where it downloads and processes media files (like audio) completely before checking size limits, allowing attackers to cause denial of service (making the server unavailable) by sending extremely large files that exhaust memory and bandwidth. The flaw affects multiple entry points, including an unauthenticated route in the Rust frontend, though there is no risk of code execution or data theft.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100650","publishedAt":"2026-09-26T14:16:47.523Z","cveId":"CVE-2026-100650","cweIds":["CWE-400"],"cvssScore":"6.5","cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-26T14:16:47.523Z","capecIds":["CAPEC-125","CAPEC-130"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}