Database/AI/ML frameworks & serving
vLLM: crafted request to the Gemma4 unified parser crashes the inference server
Impact
A remote caller with no authentication can send input that the Gemma4 unified parser mishandles, taking the vLLM server process down. On a GPU fleet that means the model replica stops serving and its GPUs sit idle until the process is restarted; in a shared cluster an attacker who can reach any public or tenant-facing vLLM endpoint can keep knocking replicas over and effectively deny other tenants the accelerators they are paying for. The record notes an exploit has been published, so this is cheap to trigger. Availability only - the record claims no confidentiality or integrity impact.
Who can reach it
Anyone who can send a request to the vLLM HTTP endpoint. No authentication required per the record's CVSS vector (PR:N), so any network path to the serving port - a tenant pod, an ingress, a misplaced LoadBalancer - is enough.
What to do
Upgrade vLLM to 0.29.1rc0 or later (fix commit 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9) and restart each serving process; replicas can be rolled one at a time behind the router, so no node drain or reboot is needed. Until then, keep vLLM endpoints off untrusted networks and front them with authentication and request rate limits. The record gives no configuration-only mitigation.
References
Related entries
- Keras (HDF5 ExternalLink, incomplete fix): Arbitrary HDF5 file readCVE-2026-12480 · Keras (HDF5 ExternalLink, incomplete fix)Medium
- Keras: unvalidated dataset sizes in .keras loading let a poisoned model exhaust node memoryCVE-2026-12570 · Keras (.keras model loading, H5IOStore.__getitem__)Medium
- Feast operator: tenant-supplied feature repo code runs with elevated privileges, reaching cluster adminCVE-2026-18942 · Feast operator in Red Hat OpenShift AI (feature repository processing)Medium
- BentoML (bentoml build, symlink dereferencing in the build context): bentoml build follows symlinks inside the buildCVE-2026-40610 · BentoML (bentoml build, symlink dereferencing in the build context)Medium
- NVIDIA NemoClaw: sensitive information visible in process invocation leads to information disclosureCVE-2026-65088 · NVIDIA NemoClaw (process invocation exposing sensitive information)Medium
- Kubeflow (Pipelines UI): Stored XSS in the pipeline viewCVE-2024-9526 · Kubeflow (Pipelines UI)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.