Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-90555

Опубликовано: 12 сент. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.

EPSS

Процентиль: 19%
0.00272
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-409

Связанные уязвимости

CVSS3: 6.5
redhat
3 дня назад

A flaw was found in vLLM. An authenticated client can exploit this vulnerability by submitting forged FLAC (Free Lossless Audio Codec) headers with an inflated sample rate to the transcription endpoint. This bypasses duration checks, leading to excessive memory allocation within the API server process. The consequence is a Denial of Service (DoS), causing the API server to crash and affecting all tenants.

CVSS3: 6.5
debian
3 дня назад

vLLM versions before 0.28.0 fail to validate audio sample rate headers ...

CVSS3: 6.5
github
3 дня назад

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.

EPSS

Процентиль: 19%
0.00272
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-409