{"data":{"id":"5fc3d78f-36c8-4bc1-8106-4da3cd88a0c5","title":"CVE-2026-100648: vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing un","summary":"vllm (a tool for running large language models) versions before 0.29.0 don't properly check the VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit, which is supposed to prevent audio files from being too large. This allows attackers to send oversized audio files to the chat system, which causes the server to use excessive memory and CPU resources when processing the audio.","solution":"Upgrade vllm to version 0.29.0 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100648","publishedAt":"2026-09-26T14:16:47.240Z","cveId":"CVE-2026-100648","cweIds":["CWE-400"],"cvssScore":"5.3","cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-26T14:16:47.240Z","capecIds":["CAPEC-125","CAPEC-130"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}