MediumVulnerabilityLLM-specific
CVE-2026-103241: vLLM denial of service through Gemma4UnifiedParser
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-103241
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.7%
Summary
A flaw in the Gemma4UnifiedParser component of vllm-project vLLM up to 0.26.0, located in rust/src/parser/src/unified/gemma4.rs, can be triggered remotely through a manipulated input to cause a denial of service. Public exploit code has been published, so the flaw can be used by attackers.
Mitigation
Upgrade to version 0.29.1rc0. The patch is commit 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised.
Topics
Related items
- HighHermes Agent - Pre-Authentication Disk ConsumptionSimilar attack · Tenable Research Advisories
- MediumHermes Agent - Pre-Authentication Memory ExhaustionSimilar attack · Tenable Research Advisories
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrlSimilar attack · GitHub Advisory Database
- MediumGHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`Similar attack · GitHub Advisory Database