Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-90713

Опубликовано: 14 сент. 2026
Источник: nvd
CVSS3: 3.3
CVSS2: 1.7
EPSS Низкий

Описание

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.

EPSS

Процентиль: 5%
0.00153
Низкий

3.3 Low

CVSS3

1.7 Low

CVSS2

Дефекты

CWE-404

Связанные уязвимости

CVSS3: 3.3
redhat
3 дня назад

A flaw was found in vLLM and tiktoken. A local attacker can exploit a vulnerability within the `TiktokenTokenizer::new` function of the tiktoken vocab File Handler component. This can lead to a denial of service, making the affected system unavailable.

CVSS3: 3.3
debian
3 дня назад

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. ...

CVSS3: 3.3
github
3 дня назад

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.

EPSS

Процентиль: 5%
0.00153
Низкий

3.3 Low

CVSS3

1.7 Low

CVSS2

Дефекты

CWE-404