Database/AI/ML frameworks & serving
vLLM (`/v1/completions` guided decoding): Invalid `json_schema` kills the server
CVSS 6.5CVE-2025-48942AI/ML frameworks & servingcurated
Impact
Invalid json_schema kills the server
Who can reach it
Unauthenticated network to an exposed serving port
What to do
Upgrade to 0.9.0+; single-request DoS against a shared serving tier
References
Related entries
- vLLM: unbounded frame count in video/jpeg base64 data URLs crashes the server with OOMCVE-2026-34755 · vLLM OpenAI-compatible API server (video/jpeg base64 multimodal path)Medium
- vLLM: no upper bound on the n parameter lets a single request OOM the API serverCVE-2026-34756 · vLLM OpenAI-compatible API server (ChatCompletionRequest/CompletionRequest n parameter)Medium
- vLLM (revision pinning): Revision pinning does not apply to all model artifactsCVE-2026-47155 · vLLM (revision pinning)Medium
- Starlette: malformed Host header makes request.url.path diverge from the routed pathCVE-2026-48710 · Starlette (Host header validation when reconstructing request.url)Medium
- vLLM - sampling parameter validation: Temperature validation uses strict comparison operators, so boundary values slipCVE-2026-54235 · vLLM - sampling parameter validationMedium
- vLLM: audio input in chat completions skips the decode-duration limit, letting a small clip OOM the workerCVE-2026-57173 · vLLM (input_audio path in /v1/chat/completions, AudioMediaIO decode duration guard)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.