Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hvv2-qg7m-ffqp

Опубликовано: 14 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 1.9
CVSS3: 3.3

Описание

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.

EPSS

Процентиль: 5%
0.00153
Низкий

1.9 Low

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-404

Связанные уязвимости

CVSS3: 3.3
redhat
3 дня назад

A flaw was found in vLLM and tiktoken. A local attacker can exploit a vulnerability within the `TiktokenTokenizer::new` function of the tiktoken vocab File Handler component. This can lead to a denial of service, making the affected system unavailable.

CVSS3: 3.3
nvd
3 дня назад

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.

CVSS3: 3.3
debian
3 дня назад

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. ...

EPSS

Процентиль: 5%
0.00153
Низкий

1.9 Low

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-404