{"data":{"id":"ba832502-297d-48d2-a886-27f1e8303070","title":"CVE-2026-105759: vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the Rust frontend's track_http_metri","summary":"vLLM, a system for running large language models, has a vulnerability in versions before 0.30.0 where an attacker can send fake HTTP method tokens (the commands in web requests) to unprotected routes, causing the system to create unlimited memory-consuming tracking records in Prometheus (a monitoring tool that tracks system performance). This eventually crashes the service by using up all available memory.","solution":"Update vLLM to version 0.30.0 or later, where this issue is fixed.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105759","publishedAt":"2026-10-05T23:17:02.760Z","cveId":"CVE-2026-105759","cweIds":["CWE-400"],"cvssScore":"5.9","cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-10-05T23:17:02.760Z","capecIds":["CAPEC-125","CAPEC-130"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}