Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-78684

Опубликовано: 25 авг. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.

EPSS

Процентиль: 26%
0.00327
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.3
redhat
23 дня назад

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.

CVSS3: 5.3
debian
23 дня назад

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU back ...

CVSS3: 5.3
github
23 дня назад

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.

EPSS

Процентиль: 26%
0.00327
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400