Dismissed
(already tracked in derivation metadata)
Permalink
CVE-2026-44223
6.5 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): None (N)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): High (H)
by @ADMIN Activity log
- Created suggestion
- @ADMIN dismissed (already tracked in derivation metadata)
vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters
vLLM is an inference and serving engine for large language models (LLMs). From to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect shape after the first decode step, causing a RuntimeError that crashes the EngineCore process. The crash is triggered when any request in the batch uses sampling penalty parameters (repetition_penalty, frequency_penalty, or presence_penalty). A single request with a penalty parameter (e.g., "repetition_penalty": 1.1) is sufficient to crash the server. This vulnerability is fixed in 0.20.0.
References
-
https://github.com/vllm-project/vllm/security/advisories/GHSA-83vm-p52w-f9pw x_refsource_CONFIRM
-
https://github.com/vllm-project/vllm/pull/38610 x_refsource_MISC
Affected products
vllm
- ==>= 0.18.0, < 0.20.0
Matching in nixpkgs
pkgs.pkgsRocm.vllm
None
-
nixos-26.05 -
- nixos-26.05-small 0.16.0
pkgs.python313Packages.vllm
None
-
nixos-26.05 -
- nixos-26.05-small 0.16.0
pkgs.pkgsRocm.python3Packages.vllm
None
-
nixos-26.05 -
- nixos-26.05-small 0.16.0