GHSA-x6mc-67gf-chw4: vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach
Summary
An attacker can crash a vLLM server running Qwen2-VL or Qwen3-VL models by sending requests with extremely high values for `max_frames` and `fps` parameters, causing the server to decode massive numbers of video frames and run out of memory. The problem exists because these Qwen video samplers (software components that extract frames from videos) don't enforce limits on these parameters, even though other video backends in the same codebase already implement such safeguards.
Solution / Mitigation
The source text does not explicitly describe a fix or mitigation for the Qwen samplers. It notes that PR #51969 fixes a related vulnerability for other backends and that commit 8b6de0eb9 (PR #54935, merged 2026-09-04) added caps to GLMGAVideoBackend using `_MAX_FRAMES` and `_MAX_FPS` class variables, but no explicit patch or version update for Qwen2-VL/Qwen3-VL is stated in the provided content.
Vulnerability Details
EPSS: 0.0%
Yes
October 5, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
CVE-2026-47482: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory
CVE-2022-29200: TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem
Original source: https://github.com/advisories/GHSA-x6mc-67gf-chw4
First tracked: October 5, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 95%