CVE-2026-100648: vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing un
Summary
vllm (a tool for running large language models) versions before 0.29.0 don't properly check the VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit, which is supposed to prevent audio files from being too large. This allows attackers to send oversized audio files to the chat system, which causes the server to use excessive memory and CPU resources when processing the audio.
Solution / Mitigation
Upgrade vllm to version 0.29.0 or later.
Vulnerability Details
5.3(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
network
low
none
none
September 26, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-47482: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory
CVE-2022-29200: TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-100648
First tracked: September 26, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 92%