Back

HIGH

vLLM 0.22.0 through 0.23.0 Denial of Service via stop_token_ids

Published Sep 26, 2026

Description

vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC frontends, allowing out-of-vocabulary token IDs to reach MinTokensLogitsProcessor. Attackers can submit requests with min_tokens greater than zero and out-of-vocabulary stop_token_ids to trigger CUDA tensor indexing failures that leave EngineCore in a fatal state requiring service restart.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Sep 26, 2026
Updated Sep 28, 2026
Reserved Sep 26, 2026

CISA Vulnrichment

Updated Sep 28, 2026

NVD

Status Analyzed
Modified Oct 6, 2026

Red Hat

Severity Important
Public date Sep 26, 2026
Bugzilla 2541838

ENISA EUVD

Assigner VulnCheck
Published Sep 26, 2026
Updated Sep 28, 2026

GitHub

No data