Database/AI/ML frameworks & serving
vLLM: structured-output request failures escape request scope and terminate the shared engine
Impact
Failures in constrained-generation handling reach EngineCore's fatal-error path instead of failing just the request. Three routes are named: a per-request backend mismatch re-raises a grammar compilation exception; padding produced by the ngram_gpu speculative-decoding mode passes a negative token into guidance validation; and the Rust frontend admits empty structured-output values that the Python frontend rejects. Any of these lets an ordinary-looking JSON-schema or grammar request kill the serving process, dropping all concurrent tenants on that replica and forcing a weight reload. Structured output is heavily used by agent and tool-calling workloads, so this is reachable in normal traffic, not only by a deliberate attacker.
Who can reach it
Any authenticated client that can send a structured-output (guided decoding / JSON schema / grammar) request over the network, CVSS AV:N/PR:L. No special configuration is needed for the frontend-validation route; the speculative-decoding route requires ngram_gpu to be enabled.
What to do
Upgrade vLLM to 0.30.0 and restart the serving replicas, rolling them to keep the endpoint available. As an interim measure, disable ngram_gpu speculative decoding and validate structured-output fields at the gateway; neither closes the grammar-backend route, so the upgrade is the real fix.
References
Related entries
- vLLM: unbounded frame count in video/jpeg base64 data URLs crashes the server with OOMCVE-2026-34755 · vLLM OpenAI-compatible API server (video/jpeg base64 multimodal path)Medium
- vLLM: no upper bound on the n parameter lets a single request OOM the API serverCVE-2026-34756 · vLLM OpenAI-compatible API server (ChatCompletionRequest/CompletionRequest n parameter)Medium
- vLLM (revision pinning): Revision pinning does not apply to all model artifactsCVE-2026-47155 · vLLM (revision pinning)Medium
- Starlette: malformed Host header makes request.url.path diverge from the routed pathCVE-2026-48710 · Starlette (Host header validation when reconstructing request.url)Medium
- vLLM - sampling parameter validation: Temperature validation uses strict comparison operators, so boundary values slipCVE-2026-54235 · vLLM - sampling parameter validationMedium
- vLLM: audio input in chat completions skips the decode-duration limit, letting a small clip OOM the workerCVE-2026-57173 · vLLM (input_audio path in /v1/chat/completions, AudioMediaIO decode duration guard)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.