CVE-2026-93592

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.5
HIGH

Description

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID triggers a CUDA device-side assertion that poisons the GPU context, causing all subsequent requests to fail until the process restarts.

Published
September 18, 2026 2:19 PM
Last Modified
September 18, 2026 2:19 PM
Source
[email protected]

Weaknesses (CWE)

CWE-129

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.