Количество 4
Количество 4
CVE-2026-54233
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcriptions endpoint limits compressed upload size but not decoded PCM output. A 25MB OPUS file expands to ~14.9GB of float32 PCM at decode time. This vulnerability is fixed in 0.23.1rc0.
CVE-2026-54233
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcriptions endpoint limits compressed upload size but not decoded PCM output. A 25MB OPUS file expands to ~14.9GB of float32 PCM at decode time. This vulnerability is fixed in 0.23.1rc0.
CVE-2026-54233
vLLM is an inference and serving engine for large language models (LLM ...
GHSA-6pr9-rp53-2pmc
vLLM: OOM Denial of Service via Audio Decompression Bomb
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-54233 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcriptions endpoint limits compressed upload size but not decoded PCM output. A 25MB OPUS file expands to ~14.9GB of float32 PCM at decode time. This vulnerability is fixed in 0.23.1rc0. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-54233 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcriptions endpoint limits compressed upload size but not decoded PCM output. A 25MB OPUS file expands to ~14.9GB of float32 PCM at decode time. This vulnerability is fixed in 0.23.1rc0. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-54233 vLLM is an inference and serving engine for large language models (LLM ... | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
GHSA-6pr9-rp53-2pmc vLLM: OOM Denial of Service via Audio Decompression Bomb | CVSS3: 6.5 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу