Database/AI/ML frameworks & serving
vLLM: video decoder limit bypass via sampler subclass shadowing exhausts unaccounted GPU memory
Impact
Decoder limits are tracked per sampler subclass, so a caller who selects different sampler subclasses in video requests gets independent counters and can allocate more hardware video decoders than the operator configured. The extra allocations consume GPU memory that vLLM does not account for, which is the memory the model weights and KV cache depend on. On a shared GPU node this pushes the serving process toward out-of-memory failures that the scheduler cannot anticipate, and the practical fix is restarting the affected server. NVD records availability impact only.
Who can reach it
Anyone who can reach the vLLM API and submit video requests; the advisory describes the attacker as unauthenticated. Attack complexity is rated high and the attack requires specific conditions, so it is not a trivial one-shot.
What to do
Upgrade vLLM to 0.29.0 or later and restart the serving processes - a rolling restart per replica, no node reboot. Meanwhile disable video input support or put the endpoint behind a gateway that authenticates and rate-limits video requests.
References
Related entries
- TrustyAI Service Operator: unauthenticated access to AI guardrail and orchestrator APIsCVE-2026-15044 · TrustyAI Service Operator (Red Hat OpenShift AI)Medium
- llama.cpp: oversized seq_id in a saved slot file leaks heap memory past the cells arrayCVE-2026-43630 · llama.cpp server (recurrent memory state slot-restore path)Medium
- vLLM: race in the prompt_embeds sparse-tensor guard reopens the CVE-2025-62164 crash pathCVE-2026-73557 · vLLM prompt_embeds loader (safe_load_prompt_embeds sparse-tensor guard)Medium
- Eclipse Che dashboard backend (POST /dashboard/api/data/resolver): The dashboard backend passes a user-supplied URLCVE-2026-86590 · Eclipse Che dashboard backend (POST /dashboard/api/data/resolver)Medium
- OpenLLM: Local file inclusion via the web applicationCVE-2024-8982 · OpenLLMMedium
- Weights & Biases OpenUI: Unauthenticated endpoints allow file upload and downloadCVE-2024-10649 · Weights & Biases OpenUIMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.