Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mpw6-hvj8-87hq

Опубликовано: 12 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.

EPSS

Процентиль: 19%
0.00272
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-409

Связанные уязвимости

CVSS3: 6.5
redhat
3 дня назад

A flaw was found in vLLM. An authenticated client can exploit this vulnerability by submitting forged FLAC (Free Lossless Audio Codec) headers with an inflated sample rate to the transcription endpoint. This bypasses duration checks, leading to excessive memory allocation within the API server process. The consequence is a Denial of Service (DoS), causing the API server to crash and affecting all tenants.

CVSS3: 6.5
nvd
3 дня назад

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.

CVSS3: 6.5
debian
3 дня назад

vLLM versions before 0.28.0 fail to validate audio sample rate headers ...

EPSS

Процентиль: 19%
0.00272
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-409