Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2026-90555

3 дня назад

A flaw was found in vLLM. An authenticated client can exploit this vulnerability by submitting forged FLAC (Free Lossless Audio Codec) headers with an inflated sample rate to the transcription endpoint. This bypasses duration checks, leading to excessive memory allocation within the API server process. The consequence is a Denial of Service (DoS), causing the API server to crash and affecting all tenants.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-90555

3 дня назад

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-90555

3 дня назад

vLLM versions before 0.28.0 fail to validate audio sample rate headers ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-mpw6-hvj8-87hq

3 дня назад

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-90555

A flaw was found in vLLM. An authenticated client can exploit this vulnerability by submitting forged FLAC (Free Lossless Audio Codec) headers with an inflated sample rate to the transcription endpoint. This bypasses duration checks, leading to excessive memory allocation within the API server process. The consequence is a Denial of Service (DoS), causing the API server to crash and affecting all tenants.

CVSS3: 6.5
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-90555

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.

CVSS3: 6.5
0%
Низкий
3 дня назад
debian логотип
CVE-2026-90555

vLLM versions before 0.28.0 fail to validate audio sample rate headers ...

CVSS3: 6.5
0%
Низкий
3 дня назад
github логотип
GHSA-mpw6-hvj8-87hq

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.

CVSS3: 6.5
0%
Низкий
3 дня назад

Уязвимостей на страницу