Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hw36-j4q7-vjxx

Опубликовано: 25 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.

EPSS

Процентиль: 25%
0.00327
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.3
redhat
23 дня назад

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.

CVSS3: 5.3
nvd
23 дня назад

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.

CVSS3: 5.3
debian
23 дня назад

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU back ...

EPSS

Процентиль: 25%
0.00327
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-400