Skip to content
MediumVulnerabilityLLM-specific

CVE-2026-103241: vLLM denial of service through Gemma4UnifiedParser

Identifier
CVE-2026-103241
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.7%

Summary

A flaw in the Gemma4UnifiedParser component of vllm-project vLLM up to 0.26.0, located in rust/src/parser/src/unified/gemma4.rs, can be triggered remotely through a manipulated input to cause a denial of service. Public exploit code has been published, so the flaw can be used by attackers.

Mitigation

Upgrade to version 0.29.1rc0. The patch is commit 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised.