CVE-2026-105760

MEDIUM CVSS 3.1: 5.3 EPSS 0.30%
Updated Oct 06, 2026
Vllm-Project
Parameter Value
CVSS 5.3 (MEDIUM)
Fixed In 0.30.0
Type CWE-400 (Uncontrolled Resource Consumption)
Vendor Vllm-Project
Public PoC No

vLLM is an inference and serving engine for large language models. Prior to 0.30.0, a caller can use the request-level media_io_kwargs field to select the GLMGA video backend and supply large values for the fps and max_frames options without a strict work ceiling. GLMGA constructs and deduplicates an attacker-sized pre-decode frame-index list, allowing a compact request and tiny valid video to consume disproportionate CPU time and memory in the shared media-loading executor. This issue is fixed in version 0.30.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Vulnerable Products

vllm-project:vllm