vllm vulnerability

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.

Published 25 Aug 2026Updated 14 Sep 20263 sources
CVSS 6.9

Source timeline

CVE record published by NVDView source ↗