MediumVulnerabilityLLM-specific
CVE-2026-105922: A security flaw has been discovered in vllm-project vLLM up to 0.31.0. This impacts the function…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-105922
- Published
- Record updated
Summary
A security flaw in vllm-project vLLM up to 0.31.0 affects the function get_token_bin_counts_and_mask in vllm/model_executor/layers/utils.py, part of the Penalty Handler component. Remote exploitation leads to denial of service, and a public exploit exists. The project was notified through an issue report but has not yet responded.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Topics
Related items
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrlSimilar attack · GitHub Advisory Database
- MediumGHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`Similar attack · GitHub Advisory Database
- HighCVE-2026-107286: Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until…Similar attack · NVD/CVE Database
- MediumPoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining BotnetSimilar attack · The Hacker News