{"data":[{"id":"9531bcf1-db3a-4a8a-94c4-94b992adbc38","title":"CVE-2026-103663: Ollama is vulnerable to path traversal in the `/api/pull` endpoint due to insufficient validation of layer digests by…","headline":"Ollama path traversal in layer digest validation of /api/pull","summary":"Ollama's /api/pull endpoint is vulnerable to path traversal because the digestToPath function does not sufficiently validate layer digests. An unauthenticated remote attacker can supply a traversal sequence as a layer digest to write a malicious binary outside the model store. Where the server process can write to /usr/lib/ollama, the file is loaded and executed on the next restart, giving remote code execution as root.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103663","publishedAt":"2026-10-08T14:16:46.187Z","severity":"critical","cvssSeverity":null,"cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-103663","cweIds":["CWE-23","CWE-913"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Ollama"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in version 0.35.0.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00714,"epssCheckedAt":"2026-10-10T06:42:02.347Z","kevDateAdded":null,"advisoryAliases":["GHSA-w8p2-phwr-px3r"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-08T14:16:46.187Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"inference","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0010"]},{"id":"bd2a6e03-f718-412a-87db-66c73656ed32","title":"CVE-2026-105922: A security flaw has been discovered in vllm-project vLLM up to 0.31.0. This impacts the function…","headline":"vLLM denial of service in Penalty Handler token bin counting","summary":"A security flaw in vllm-project vLLM up to 0.31.0 affects the function get_token_bin_counts_and_mask in vllm/model_executor/layers/utils.py, part of the Penalty Handler component. Remote exploitation leads to denial of service, and a public exploit exists. The project was notified through an issue report but has not yet responded.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105922","publishedAt":"2026-10-06T15:17:17.727Z","severity":"medium","cvssSeverity":"medium","cvssScore":"4.3","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-105922","cweIds":["CWE-404"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["denial_of_service"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00303,"epssCheckedAt":"2026-10-10T02:56:51.777Z","kevDateAdded":null,"advisoryAliases":["GHSA-x9pq-jx6q-p3qv"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-06T15:17:17.727Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"e28ce988-5e07-4afc-975a-022ac61e888a","title":"CVE-2026-105775: A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function…","headline":"vLLM out-of-bounds read in conv_ssm_forward via Completions Request Handler","summary":"A security vulnerability in vllm-project vLLM up to 0.31.0 affects the function conv_ssm_forward in vllm/model_executor/layers/mamba/mamba_mixer2.py, within the Completions Request Handler component. Manipulation of this component leads to an out-of-bounds read, and the attack can be carried out remotely. The exploit has been publicly disclosed and may be used, and the project was informed through an issue report but has not yet responded.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105775","publishedAt":"2026-10-06T06:17:00.280Z","severity":"medium","cvssSeverity":"medium","cvssScore":"4.3","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-105775","cweIds":["CWE-119","CWE-125"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00296,"epssCheckedAt":"2026-10-10T02:58:12.571Z","kevDateAdded":null,"advisoryAliases":["GHSA-qx62-jwpf-rcpj"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-06T06:17:00.280Z","capecIds":["CAPEC-100","CAPEC-540"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"a7ef43c7-3fd4-4754-8179-9bf2dab44ab6","title":"GHSA-x6mc-67gf-chw4: vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach","headline":null,"summary":"An unauthenticated attacker can exhaust memory in the vLLM API-server process on Qwen2-VL and Qwen3-VL deployments by raising the request-level media_io_kwargs.video.max_frames and fps values. The Qwen video samplers never read num_frames, so the num_frames ceiling in PR #51969 does not stop this path, while the same knobs were already capped for GLMGAVideoBackend in commit 8b6de0eb9. In the reporter's test, 74 extra bytes of JSON sent over POST /tokenize raised peak RSS from 2 271 MiB to 13 629 MiB.","sourceUrl":"https://github.com/advisories/GHSA-x6mc-67gf-chw4","publishedAt":"2026-10-05T23:42:59.000Z","severity":"medium","cvssSeverity":"medium","cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-105758","cweIds":null,"affectedPackages":["vllm@>= 0.24.0, < 0.30.0 (fixed: 0.30.0)"],"affectedVendors":[],"affectedVendorsRaw":["vLLM","Qwen2-VL","Qwen3-VL"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["denial_of_service"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00303,"epssCheckedAt":"2026-10-10T06:42:03.742Z","kevDateAdded":null,"advisoryAliases":["GHSA-x6mc-67gf-chw4"],"affectedPackagesSource":null,"patchAvailable":true,"disclosureDate":"2026-10-05T23:42:59.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null},{"id":"9a5d4781-24cc-4005-9a39-e88ae3c759be","title":"GHSA-58v5-2m8f-94pr: vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion","headline":null,"summary":"vLLM's OpenAI-compatible chat endpoint accepts request-level `media_io_kwargs`, so a caller can select the GLMGA video sampler and set large `fps` and `max_frames` values. GLMGA builds and deduplicates an attacker-sized index list before frame reads, so a tiny valid video with compact JSON options can consume disproportionate CPU and memory in the shared media-loading executor and delay unrelated media requests. The demonstrated impact is partial denial of service, with no memory corruption, data disclosure or code execution claimed.","sourceUrl":"https://github.com/advisories/GHSA-58v5-2m8f-94pr","publishedAt":"2026-10-05T23:42:55.000Z","severity":"medium","cvssSeverity":"medium","cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-105760","cweIds":null,"affectedPackages":["vllm@>= 0.23.0rc2, < 0.30.0 (fixed: 0.30.0)"],"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Validate request-level video sampling options before dispatching work to the media executor. Enforce conservative absolute limits for `fps`, `max_frames`, and especially the computed candidate count.","attackType":["denial_of_service"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00302,"epssCheckedAt":"2026-10-10T06:42:02.840Z","kevDateAdded":null,"advisoryAliases":["GHSA-58v5-2m8f-94pr"],"affectedPackagesSource":null,"patchAvailable":true,"disclosureDate":"2026-10-05T23:42:55.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null},{"id":"d60747e4-2dae-4873-9366-7b3929e04073","title":"GHSA-ph72-cqr5-qpp7: vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features","headline":null,"summary":"vLLM versions up to and including 0.25.1 are affected through the disaggregated scale-out transport. The POST /inference/v1/generate route decodes a caller-supplied features object (kwargs_data, mm_hashes, mm_placeholders) and passes it to the engine as if it came from the trusted render step, without validating it against the active model's renderer output. Any authenticated caller can forge one field to crash the shared EngineCore process, poison or disclose cross-request encoder-cache state, or drop placeholder masks during replay.","sourceUrl":"https://github.com/advisories/GHSA-ph72-cqr5-qpp7","publishedAt":"2026-10-05T23:42:50.000Z","severity":"medium","cvssSeverity":"medium","cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-105754","cweIds":null,"affectedPackages":["vllm@< 0.30.0 (fixed: 0.30.0)"],"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["denial_of_service","data_extraction"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00269,"epssCheckedAt":"2026-10-10T02:57:39.298Z","kevDateAdded":null,"advisoryAliases":["GHSA-ph72-cqr5-qpp7"],"affectedPackagesSource":null,"patchAvailable":true,"disclosureDate":"2026-10-05T23:42:50.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","availability","integrity"],"aiComponentTargeted":"inference","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null},{"id":"c88c3c60-3772-4363-adf0-ecb261768e41","title":"GHSA-85xf-c7hm-whqw: vLLM: Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service (3 sites)","headline":null,"summary":"vLLM versions up to and including 0.25.1 contain three structured-output request paths that raise an uncaught, engine-fatal exception instead of a per-request validation error. The exception escapes into EngineCore's busy loop and triggers a fatal _send_engine_dead(), so one malformed structured-output request denies service to all concurrent and subsequent users of that engine. Site 1 is a valid duplicate-root EBNF grammar that the latched xgrammar backend fails to compile, and the completion check catches only TimeoutError. The advisory states that these sites are distinct from the fixes in GHSA-6qc9-v4r8-22xg and GHSA-8wr5-jm2h-8r4f.","sourceUrl":"https://github.com/advisories/GHSA-85xf-c7hm-whqw","publishedAt":"2026-10-05T23:42:44.000Z","severity":"medium","cvssSeverity":"medium","cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-105757","cweIds":null,"affectedPackages":["vllm@< 0.30.0 (fixed: 0.30.0)"],"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["denial_of_service"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00314,"epssCheckedAt":"2026-10-10T02:57:07.563Z","kevDateAdded":null,"advisoryAliases":["GHSA-85xf-c7hm-whqw"],"affectedPackagesSource":null,"patchAvailable":true,"disclosureDate":"2026-10-05T23:42:44.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null},{"id":"4eeacfc6-0ee7-4e8e-8d88-445fdf4b1240","title":"GHSA-2phq-3phc-84px: vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`","headline":null,"summary":"vLLM versions up to and including 0.25.1 cache late-interaction query embeddings on `/score` and `/rerank` under a key derived from the caller-supplied `X-Request-Id` header when flash late interaction is enabled, which is the default for supported models. A concurrent request reusing the victim's header value replaces the victim's cached query embedding, so the victim's documents are scored against the attacker's query, and one request can also force the other into a late-interaction cache-miss error. The source states the lower bound of affected versions is not confirmed and maintainers can confirm it.","sourceUrl":"https://github.com/advisories/GHSA-2phq-3phc-84px","publishedAt":"2026-10-05T23:42:39.000Z","severity":"medium","cvssSeverity":"medium","cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-105755","cweIds":null,"affectedPackages":["vllm@< 0.30.0 (fixed: 0.30.0)"],"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00202,"epssCheckedAt":"2026-10-10T03:00:41.257Z","kevDateAdded":null,"advisoryAliases":["GHSA-2phq-3phc-84px"],"affectedPackagesSource":null,"patchAvailable":true,"disclosureDate":"2026-10-05T23:42:39.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":"inference","llmSpecific":false,"classifierConfidence":0.93,"researchCategory":null,"atlasIds":null},{"id":"ac355ee9-ff2f-45ac-bfde-82e2679b84ff","title":"GHSA-2823-qmq8-rwvj: vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service","headline":null,"summary":"vLLM's OpenAI-compatible request models (Completions, Chat Completions, Responses) accept a client-supplied `cache_salt` validated only as a non-empty string. With the built-in LMCache-MP KV connector enabled, the value reaches the scheduler's cache lookup unguarded, and the downstream LMCache `IPCCacheServerKey.__post_init__` raises an uncaught `ValueError` for `@`, `/`, `\\`, NUL or lengths over 128 characters. Because the exception is never caught on the scheduling path, a single request such as `cache_salt=\"/\"` kills EngineCore for all users.","sourceUrl":"https://github.com/advisories/GHSA-2823-qmq8-rwvj","publishedAt":"2026-10-05T23:42:34.000Z","severity":"medium","cvssSeverity":"medium","cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-105756","cweIds":null,"affectedPackages":["vllm@< 0.30.0 (fixed: 0.30.0)"],"affectedVendors":[],"affectedVendorsRaw":["vLLM","LMCache"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["denial_of_service"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00314,"epssCheckedAt":"2026-10-10T02:56:03.326Z","kevDateAdded":null,"advisoryAliases":["GHSA-2823-qmq8-rwvj"],"affectedPackagesSource":null,"patchAvailable":true,"disclosureDate":"2026-10-05T23:42:34.000Z","capecIds":null,"crossRefCount":1,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null},{"id":"ba832502-297d-48d2-a886-27f1e8303070","title":"CVE-2026-105759: vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the Rust frontend's…","headline":"vLLM Rust frontend memory exhaustion via unique HTTP method labels in metrics","summary":"vLLM, an inference and serving engine for large language models, is affected before version 0.30.0 by a flaw in the Rust frontend's track_http_metrics middleware. The middleware records the raw HTTP method token as a Prometheus label on requests reaching registered routes, so an unauthenticated attacker sending unique arbitrary method tokens to unguarded routes such as /tokenize can permanently create label sets. This increases process memory usage and enlarges the /metrics response until the service or monitoring path is exhausted.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105759","publishedAt":"2026-10-05T23:17:02.760Z","severity":"medium","cvssSeverity":"medium","cvssScore":"5.9","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-105759","cweIds":["CWE-400"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in version 0.30.0.","attackType":["denial_of_service"],"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00332,"epssCheckedAt":"2026-10-10T02:56:35.067Z","kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-05T23:17:02.760Z","capecIds":["CAPEC-125","CAPEC-130"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null},{"id":"9eb610b1-3590-4426-8047-cff25abff510","title":"CVE-2026-105753: vLLM is an inference and serving engine for large language models. Prior to 0.28.0, the default mirrored multimodal LRU…","headline":"vLLM denial of service via multimodal cache hash reuse","summary":"CVE-2026-105753 affects vLLM, an inference and serving engine for large language models, prior to 0.28.0. The default mirrored multimodal LRU cache can record a media hash in the frontend sender cache before engine admission, while the engine receiver cache never gets the payload if the request is rejected. A later request reusing that media hash makes the receiver cache hit an assertion, causing an availability failure in the shared service.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105753","publishedAt":"2026-10-05T23:17:01.867Z","severity":"medium","cvssSeverity":"medium","cvssScore":"6.5","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-105753","cweIds":["CWE-617"],"affectedPackages":["vllm@< 0.28.0 (fixed: 0.28.0)"],"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in version 0.28.0.","attackType":["denial_of_service"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00427,"epssCheckedAt":"2026-10-10T06:42:03.263Z","kevDateAdded":null,"advisoryAliases":["GHSA-ph3r-5jfg-f84f"],"affectedPackagesSource":"ghsa","patchAvailable":true,"disclosureDate":"2026-10-05T23:17:01.867Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null},{"id":"7b97b299-f7ba-4f2b-8174-2a5d7f2287f1","title":"CVE-2026-105752: vLLM is an inference and serving engine for large language models. Prior to 0.30.0, Harmony tool continuations…","headline":"vLLM prefix cache isolation bypass in Harmony tool continuations","summary":"vLLM versions prior to 0.30.0 drop the cache_salt value when rebuilding the next-turn engine input for Harmony tool continuations submitted through POST /v1/responses. The continuation prefix lands in the global unsalted cache namespace even when the caller enabled salting, and on deployments with prefix caching enabled (the default), an authenticated tenant can use the cached_tokens_per_turn count to determine whether a victim's low-entropy post-tool prefix was previously processed, defeating salted prefix cache isolation.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105752","publishedAt":"2026-10-05T23:17:01.710Z","severity":"low","cvssSeverity":"low","cvssScore":"3.1","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-105752","cweIds":["CWE-200","CWE-524"],"affectedPackages":["vllm@< 0.30.0 (fixed: 0.30.0)"],"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in version 0.30.0.","attackType":["data_extraction"],"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00216,"epssCheckedAt":"2026-10-10T06:42:00.270Z","kevDateAdded":null,"advisoryAliases":["GHSA-935w-9g4m-p28p"],"affectedPackagesSource":"ghsa","patchAvailable":true,"disclosureDate":"2026-10-05T23:17:01.710Z","capecIds":["CAPEC-116"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"57f9bd65-0045-4cf6-8bd0-64b311f4e930","title":"CVE-2026-103241: A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file…","headline":"vLLM denial of service through Gemma4UnifiedParser","summary":"A flaw in the Gemma4UnifiedParser component of vllm-project vLLM up to 0.26.0, located in rust/src/parser/src/unified/gemma4.rs, can be triggered remotely through a manipulated input to cause a denial of service. Public exploit code has been published, so the flaw can be used by attackers.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103241","publishedAt":"2026-09-30T17:16:42.570Z","severity":"medium","cvssSeverity":"medium","cvssScore":"5.3","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-103241","cweIds":["CWE-404"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Upgrade to version 0.29.1rc0. The patch is commit 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised.","attackType":["denial_of_service"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00714,"epssCheckedAt":"2026-10-10T06:41:57.681Z","kevDateAdded":null,"advisoryAliases":["GHSA-328r-mpfv-qc55"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-30T17:16:42.570Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null},{"id":"b5bd1afa-50ea-4dca-9180-61f4065ba221","title":"CVE-2026-102697: Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode…","headline":"Ollama agent mode Bash tool approval bypass via shell operators","summary":"Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization flaw in the experimental agent mode Bash tool approval mechanism, which fails to properly parse shell syntax. An attacker who can influence model output through prompt injection can append control operators such as semicolons or logical operators to an approved command, executing additional shell commands and bypassing the session approval requirement.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102697","publishedAt":"2026-09-29T17:17:08.150Z","severity":"high","cvssSeverity":"high","cvssScore":"7.8","labels":["security","industry"],"issueType":"vulnerability","cveId":"CVE-2026-102697","cweIds":["CWE-863"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Ollama"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["prompt_injection","other"],"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"local","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00146,"epssCheckedAt":"2026-10-10T02:56:35.067Z","kevDateAdded":null,"advisoryAliases":["GHSA-44m8-pr79-3734"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-29T17:17:08.150Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0051"]},{"id":"affdd0ea-ac66-483a-b16d-dcf93b3551e9","title":"GHSA-456v-xq2p-r4cj: code-ollama: `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78)","headline":null,"summary":"The `grep_search` tool in `code-ollama` builds a shell command by interpolating attacker-controlled `pattern` and `path` arguments and runs it through `child_process.exec()`. Its sanitization escapes only backslashes and double quotes, so `$()` and backtick substitution pass through, allowing arbitrary OS command execution with the privileges of the local user. Because `grep_search` is treated as read-only, it runs automatically in Plan mode without an approval prompt.","sourceUrl":"https://github.com/advisories/GHSA-456v-xq2p-r4cj","publishedAt":"2026-09-28T13:59:43.000Z","severity":"high","cvssSeverity":"high","cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":null,"cweIds":null,"affectedPackages":["code-ollama@<= 0.36.0 (fixed: 0.36.1)"],"affectedVendors":[],"affectedVendorsRaw":["code-ollama","Ollama"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":["GHSA-456v-xq2p-r4cj"],"affectedPackagesSource":null,"patchAvailable":true,"disclosureDate":"2026-09-28T13:59:43.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"plugin","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"1395ba45-f52b-4be1-adb6-4dca4ca627be","title":"CVE-2026-100654: vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST…","headline":"vLLM denial of service via stop_token_ids in completion endpoints","summary":"vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/chat/completions endpoints, validating only that the values are integers rather than that each id falls within the model vocabulary or logits range. When min_tokens is greater than 0, an out-of-range id reaches a CUDA index_put_ operation and triggers a device-side assertion. An authenticated API user can send one malformed request that returns 500 Internal Server Error and leaves EngineCore in a fatal state, so later requests fail until the service restarts (denial of service).","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100654","publishedAt":"2026-09-26T14:16:48.100Z","severity":"medium","cvssSeverity":"medium","cvssScore":"6.5","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-100654","cweIds":["CWE-129"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["denial_of_service"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00314,"epssCheckedAt":"2026-10-10T03:00:37.498Z","kevDateAdded":null,"advisoryAliases":["GHSA-9fp6-6v59-w2jx"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-26T14:16:48.100Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null},{"id":"25987ef1-f8ba-4046-bae3-6945afff7ef7","title":"CVE-2026-100653: vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the…","headline":"vLLM unpinned Hugging Face artifact loads for FunAudioChat and Tarsier2","summary":"CVE-2026-100653 affects vLLM versions 0.22.1 through 0.28.0. The operator-supplied model revision pin (--revision / --code-revision) is not applied to several Hugging Face artifact loads for the FunAudioChat and Tarsier2 architectures, including the WhisperFeatureExtractor and speech_tokenizer loads in vllm/model_executor/models/funaudiochat.py and the Qwen2VLConfig.from_pretrained call in vllm/model_executor/models/qwen2_vl.py. Pinned deployments therefore resolve these artifacts from the repository's default revision, so upstream changes can alter audio preprocessing, speech tokenizer behavior, or Tarsier2 configuration without any change to the pin.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100653","publishedAt":"2026-09-26T14:16:47.953Z","severity":"medium","cvssSeverity":"medium","cvssScore":"6.5","labels":["security","industry"],"issueType":"vulnerability","cveId":"CVE-2026-100653","cweIds":["CWE-348"],"affectedPackages":null,"affectedVendors":["HuggingFace"],"affectedVendorsRaw":["vLLM","Hugging Face","FunAudioChat","Tarsier2","Qwen2VLConfig","WhisperFeatureExtractor"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in 0.28.0.","attackType":["supply_chain"],"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00284,"epssCheckedAt":"2026-10-10T03:00:38.957Z","kevDateAdded":null,"advisoryAliases":["GHSA-r3cf-2wgr-7xh9"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-26T14:16:47.953Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0010"]},{"id":"d58a2e12-6c57-4263-8950-5237f43910f0","title":"CVE-2026-100652: vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC…","headline":"vLLM stop_token_ids validation flaw in Rust HTTP and gRPC frontends","summary":"vLLM versions 0.22.0 through 0.23.0 do not validate stop_token_ids against vocabulary bounds in the Rust HTTP and gRPC frontends, so out-of-vocabulary token IDs reach MinTokensLogitsProcessor. An attacker can send requests with min_tokens greater than zero and out-of-vocabulary stop_token_ids to trigger CUDA tensor indexing failures, which leave EngineCore in a fatal state that requires a service restart.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100652","publishedAt":"2026-09-26T14:16:47.810Z","severity":"medium","cvssSeverity":"medium","cvssScore":"5.9","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-100652","cweIds":["CWE-20"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["denial_of_service"],"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00361,"epssCheckedAt":"2026-10-10T02:57:39.298Z","kevDateAdded":null,"advisoryAliases":["GHSA-gxcm-7c4h-f56c"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-26T14:16:47.810Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null},{"id":"a0dc1847-d74c-4544-9bc0-b1f0c03edc93","title":"CVE-2026-100651: vLLM before 0.29.0 fails to enforce decoder prompt-length validation on the disaggregated serving endpoint…","headline":"vLLM denial of service via overlong prompt on disaggregated generate endpoint","summary":"vLLM versions before 0.29.0 do not enforce decoder prompt-length validation on the disaggregated serving endpoint /inference/v1/generate when a request includes a 'features' multimodal payload. The GenerateRequest.token_ids list is not checked against model_config.max_model_len, and processors reporting skip_prompt_length_check=True (such as Nemotron Parse, Whisper, and FireRedLID) bypass validation entirely. A client that can reach the endpoint on an affected configuration can submit an overlong token_ids list and crash the worker, causing denial of service.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100651","publishedAt":"2026-09-26T14:16:47.663Z","severity":"medium","cvssSeverity":"medium","cvssScore":"6.5","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-100651","cweIds":["CWE-400"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in 0.29.0.","attackType":["denial_of_service"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00331,"epssCheckedAt":"2026-10-10T06:42:03.263Z","kevDateAdded":null,"advisoryAliases":["GHSA-g43f-v3gj-45x5"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-26T14:16:47.663Z","capecIds":["CAPEC-125","CAPEC-130"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null},{"id":"3db0173d-9a93-44dc-bf7c-daa91b146177","title":"CVE-2026-100650: vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media…","headline":"vLLM media fetching exhausts memory and bandwidth before size limits apply","summary":"vLLM through 0.29.0 fetches and fully reads remote or inline media before enforcing its documented media controls, the VLLM_MAX_AUDIO_CLIP_FILESIZE_MB audio size cap and the --limit-mm-per-prompt item limits. Across four ingress paths, including the chat completions audio_url and base64 path and the unauthenticated Rust frontend POST /tokenize route, a remote attacker can force memory and outbound bandwidth use proportional to an attacker-chosen body size or media item count before rejection. The result is pre-inference memory and bandwidth exhaustion, a denial of service. The source states no code execution or data disclosure impact.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100650","publishedAt":"2026-09-26T14:16:47.523Z","severity":"medium","cvssSeverity":"medium","cvssScore":"6.5","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-100650","cweIds":["CWE-400"],"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["denial_of_service"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00653,"epssCheckedAt":"2026-10-10T03:00:40.088Z","kevDateAdded":null,"advisoryAliases":["GHSA-j8gm-f3cq-6c27"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-26T14:16:47.523Z","capecIds":["CAPEC-125","CAPEC-130"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.93,"researchCategory":null,"atlasIds":null}],"meta":{"total":222,"limit":20,"offset":0}}