Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-78684

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.

A flaw was found in vLLM. Unauthenticated attackers can exploit this vulnerability by activating the DeepStream backend during a request. This allows them to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, leading to a partial denial of service for concurrent requests.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-gaudi-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-neuron-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2523362vllm: vLLM: Denial of Service via DeepStream backend resource control bypass.

EPSS

Процентиль: 25%
0.00327
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
23 дня назад

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.

CVSS3: 5.3
debian
23 дня назад

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU back ...

CVSS3: 5.3
github
23 дня назад

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.

EPSS

Процентиль: 25%
0.00327
Низкий

5.3 Medium

CVSS3