CVE-2026-100653: vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-
Summary
vLLM (an engine for running large language models) versions 0.22.1 through 0.28.0 have a bug where certain model settings are not applied correctly for two specific model types (FunAudioChat and Tarsier2). When operators pin their deployments to a specific version for safety, the system still pulls some components (tokenizers and configs, which control how audio is processed) from the default upstream version instead, meaning unexpected changes to the base repository could alter how the model behaves without the operator knowing.
Solution / Mitigation
The issue is fixed in version 0.28.0.
Vulnerability Details
6.5(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
network
high
none
none
September 26, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-100653
First tracked: September 26, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 95%