Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-54233

Опубликовано: 22 июн. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcriptions endpoint limits compressed upload size but not decoded PCM output. A 25MB OPUS file expands to ~14.9GB of float32 PCM at decode time. This vulnerability is fixed in 0.23.1rc0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vllm:vllm:*:-:*:*:*:*:*:*
Версия до 0.23.1 (исключая)

EPSS

Процентиль: 35%
0.00422
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-409

Связанные уязвимости

CVSS3: 6.5
redhat
около 1 месяца назад

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcriptions endpoint limits compressed upload size but not decoded PCM output. A 25MB OPUS file expands to ~14.9GB of float32 PCM at decode time. This vulnerability is fixed in 0.23.1rc0.

CVSS3: 6.5
debian
около 1 месяца назад

vLLM is an inference and serving engine for large language models (LLM ...

CVSS3: 6.5
github
около 2 месяцев назад

vLLM: OOM Denial of Service via Audio Decompression Bomb

EPSS

Процентиль: 35%
0.00422
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-409