Database/AI/ML frameworks & serving
vLLM: GLMGA video backend builds an attacker-sized frame-index list, starving the shared media loader
Impact
A caller can use the request-level media_io_kwargs field to select the GLMGA video backend and pass large fps and max_frames values with no strict work ceiling. GLMGA then constructs and deduplicates a frame-index list sized by the caller, so a compact request with a tiny valid video can consume disproportionate CPU time and memory inside the shared media-loading executor. Because that executor is shared, one tenant's request degrades media handling for everyone on the replica while the GPUs wait on input. Availability impact only, per the advisory; distinct from the Qwen video-backend ceiling issue in the same release.
Who can reach it
A caller able to submit requests carrying media_io_kwargs to an affected vLLM frontend. The CVSS vector indicates low-privilege authentication (PR:L).
What to do
Upgrade to vLLM 0.30.0 and restart the serving processes; all versions prior to 0.30.0 are affected. Frontend-level change, so rolling replicas is enough - no node drain or reboot. Interim mitigation is to reject or normalise media_io_kwargs at the gateway.
References
Related entries
- BentoML OpenLLM 0.6.30 (async_run_command in src/openllm/common.py): A model repository directory name flows unescapedCVE-2026-15035 · BentoML OpenLLM 0.6.30 (async_run_command in src/openllm/common.py)Medium
- JupyterHub: unauthenticated logins write unbounded usernames to the log, exhausting storageCVE-2026-54338 · JupyterHub form-based login authenticators (failed-login logging)Medium
- vLLM: malformed JSON to the OpenAI-compatible endpoints returns server paths and versionsCVE-2026-73555 · vLLM OpenAI-compatible API server (validation_exception_handler, sanitize_message)Medium
- vLLM: attacker-supplied structured-output regex pins a CPU core and stalls the engine pathCVE-2026-73556 · vLLM structured outputs, lm-format-enforcer backend (structured_outputs.regex)Medium
- vLLM: integer overflow in the activation CUDA kernel leaks another batched request's outputCVE-2026-73558 · vLLM CUDA activation kernels (act_and_mul_kernel, activation_kernels.cu)Medium
- vLLM (DeepStream video backend, VideoMediaIO backend selection): A performance feature merged past two existingNCVD-2026-044-vllm-deepstream-video-backend-vi · vLLM (DeepStream video backend, VideoMediaIO backend selection)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.