CVE-2026-105759

MEDIUM CVSS 3.1: 5.9 EPSS 0.33%
Updated Oct 06, 2026
Vllm-Project
Parameter Value
CVSS 5.9 (MEDIUM)
Fixed In 0.30.0
Type CWE-400 (Uncontrolled Resource Consumption)
Vendor Vllm-Project
Public PoC No

vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the Rust frontend's track_http_metrics middleware records the raw HTTP method token as a Prometheus label for requests reaching registered routes. An unauthenticated attacker can send unique arbitrary method tokens to unguarded routes such as /tokenize, causing Prometheus's Family::get_or_create function to permanently create counter and histogram label sets.

Those label sets increase process memory usage and enlarge the /metrics response until the service or monitoring path is exhausted. This issue is fixed in version 0.30.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products

vllm-project:vllm