Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-90713

Опубликовано: 14 сент. 2026
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

A flaw was found in vLLM and tiktoken. A local attacker can exploit a vulnerability within the TiktokenTokenizer::new function of the tiktoken vocab File Handler component. This can lead to a denial of service, making the affected system unavailable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Out of support scope
Exploit Intelligenceexploit-intelligence/vulnerability-analysis-rhel9Out of support scope
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Fix deferred
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2533014vllm: tiktoken: vLLM and tiktoken: Local Denial of Service vulnerability

EPSS

Процентиль: 5%
0.00153
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
nvd
3 дня назад

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.

CVSS3: 3.3
debian
3 дня назад

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. ...

CVSS3: 3.3
github
3 дня назад

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.

EPSS

Процентиль: 5%
0.00153
Низкий

3.3 Low

CVSS3