GPU VulnDB

Database/AI/ML frameworks & serving

vLLM: GLMGA video backend builds an attacker-sized frame-index list, starving the shared media loader

CVSS 5.3CVE-2026-105760AI/ML frameworks & servingcurated

Impact

A caller can use the request-level media_io_kwargs field to select the GLMGA video backend and pass large fps and max_frames values with no strict work ceiling. GLMGA then constructs and deduplicates a frame-index list sized by the caller, so a compact request with a tiny valid video can consume disproportionate CPU time and memory inside the shared media-loading executor. Because that executor is shared, one tenant's request degrades media handling for everyone on the replica while the GPUs wait on input. Availability impact only, per the advisory; distinct from the Qwen video-backend ceiling issue in the same release.

Who can reach it

A caller able to submit requests carrying media_io_kwargs to an affected vLLM frontend. The CVSS vector indicates low-privilege authentication (PR:L).

What to do

Upgrade to vLLM 0.30.0 and restart the serving processes; all versions prior to 0.30.0 are affected. Frontend-level change, so rolling replicas is enough - no node drain or reboot. Interim mitigation is to reject or normalise media_io_kwargs at the gateway.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.