{"data":{"id":"a0dc1847-d74c-4544-9bc0-b1f0c03edc93","title":"CVE-2026-100651: vLLM before 0.29.0 fails to enforce decoder prompt-length validation on the disaggregated serving endpoint /inference/v1","summary":"vLLM versions before 0.29.0 have a vulnerability where the /inference/v1/generate endpoint doesn't properly check if decoder prompts (the input text converted to tokens) are too long for the model when processing multimodal requests (requests with images, audio, or other non-text data). Certain multimodal processors skip this length validation entirely, allowing attackers to send excessively long token sequences that crash the system and cause a denial of service (making the service unavailable).","solution":"Fixed in vLLM version 0.29.0.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100651","publishedAt":"2026-09-26T14:16:47.663Z","cveId":"CVE-2026-100651","cweIds":["CWE-400"],"cvssScore":"6.5","cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM","Nemotron Parse","Whisper","FireRedLID"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-26T14:16:47.663Z","capecIds":["CAPEC-125","CAPEC-130"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}