CVE-2026-100649: vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler sub | AI Sec Watch