CVE-2026-100652: vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC fron
Summary
vLLM versions 0.22.0 through 0.23.0 have a bug where they don't check if stop_token_ids (tokens that tell the AI to stop generating text) are valid for the model's vocabulary. Attackers can exploit this by sending requests with invalid token IDs, which causes the system to crash and requires restarting the service.
Vulnerability Details
5.9(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
network
high
none
none
September 26, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-47482: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory
CVE-2022-29200: TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-100652
First tracked: September 26, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 95%