CVE-2026-105758

MEDIUM CVSS 3.1: 5.3 EPSS 0.31%
Updated Oct 06, 2026
Vllm-Project
Parameter Value
CVSS 5.3 (MEDIUM)
Fixed In 0.30.0
Type CWE-770 (Allocation Without Limits)
Vendor Vllm-Project
Public PoC No

vLLM is an inference and serving engine for large language models. From 0.24.0 until 0.30.0, the Qwen2VLVideoBackend and Qwen3VLVideoBackend classes accept request-level values for the media_io_kwargs.video.max_frames and media_io_kwargs.video.fps fields without enforcing server-side ceilings. An unauthenticated caller can submit these values to the /tokenize endpoint, causing the sampler to decode every frame selected from attacker-controlled video input, consume disproportionate frontend memory, and potentially terminate the API process before scheduling or admission control.

The Rust frontend is not affected because it rejects the media_io_kwargs field. This issue is fixed in version 0.30.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Vulnerable Products

vllm-project:vllm