{"data":{"id":"a7ef43c7-3fd4-4754-8179-9bf2dab44ab6","title":"GHSA-x6mc-67gf-chw4: vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach","summary":"An attacker can crash a vLLM server running Qwen2-VL or Qwen3-VL models by sending requests with extremely high values for `max_frames` and `fps` parameters, causing the server to decode massive numbers of video frames and run out of memory. The problem exists because these Qwen video samplers (software components that extract frames from videos) don't enforce limits on these parameters, even though other video backends in the same codebase already implement such safeguards.","solution":"The source text does not explicitly describe a fix or mitigation for the Qwen samplers. It notes that PR #51969 fixes a related vulnerability for other backends and that commit 8b6de0eb9 (PR #54935, merged 2026-09-04) added caps to GLMGAVideoBackend using `_MAX_FRAMES` and `_MAX_FPS` class variables, but no explicit patch or version update for Qwen2-VL/Qwen3-VL is stated in the provided content.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-x6mc-67gf-chw4","publishedAt":"2026-10-05T23:42:59.000Z","cveId":"CVE-2026-105758","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":["vllm@>= 0.24.0, < 0.30.0 (fixed: 0.30.0)"],"affectedVendors":[],"affectedVendorsRaw":["vLLM","Qwen2-VL","Qwen3-VL"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-10-05T23:42:59.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}