Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-90555

Опубликовано: 12 сент. 2026
Источник: debian
EPSS Низкий

Описание

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vllmitppackage

EPSS

Процентиль: 19%
0.00272
Низкий

Связанные уязвимости

CVSS3: 6.5
redhat
3 дня назад

A flaw was found in vLLM. An authenticated client can exploit this vulnerability by submitting forged FLAC (Free Lossless Audio Codec) headers with an inflated sample rate to the transcription endpoint. This bypasses duration checks, leading to excessive memory allocation within the API server process. The consequence is a Denial of Service (DoS), causing the API server to crash and affecting all tenants.

CVSS3: 6.5
nvd
3 дня назад

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.

CVSS3: 6.5
github
3 дня назад

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.

EPSS

Процентиль: 19%
0.00272
Низкий