{"data":{"id":"9603e19b-3ea9-4c9f-9689-0298f9b3a9d6","title":"CVE-2026-100649: vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler sub","summary":"vLLM (a system for running large language models) versions before 0.29.0 have a security flaw in its video processing component where attackers can bypass resource limits by selecting different sampler subclasses (variations of code that handle sampling) in video requests, causing the system to use more GPU memory than it should. Unauthenticated attackers (those without login credentials) can exploit this to crash or degrade the service by exhausting available GPU resources.","solution":"Update vLLM to version 0.29.0 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100649","publishedAt":"2026-09-26T14:16:47.380Z","cveId":"CVE-2026-100649","cweIds":["CWE-770"],"cvssScore":"3.7","cvssSeverity":"low","severity":"low","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-26T14:16:47.380Z","capecIds":["CAPEC-130"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}