CVE-2026-105922
vllm-project vLLM Penalty utils.py get_token_bin_counts_and_mask denial of service
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
A security flaw has been discovered in vllm-project vLLM up to 0.31.0. This impacts the function get_token_bin_counts_and_mask of the file vllm/model_executor/layers/utils.py of the component Penalty Handler. Performing a manipulation results in denial of service. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
| CWE | CWE-404 |
| Vendor | vllm-project |
| Product | vllm |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for vllm-project vllm
Be the first to know when new medium vulnerabilities affecting vllm-project vllm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
vllm-project / vLLM
0.1 0.2 0.3 0.4 0.5 0.6 0.7 0.8 0.9 0.10 0.11 0.12 0.13 0.14 0.15 0.16 0.17 0.18 0.19 0.20 0.21 0.22 0.23 0.24 0.25 0.26 0.27 0.28 0.29 0.30 0.31.0
References
vuldb.com: https://vuldb.com/vuln/413896 vuldb.com: https://vuldb.com/vuln/413896/cti vuldb.com: https://vuldb.com/cve/CVE-2026-105922 vuldb.com: https://vuldb.com/submit/992707 github.com: https://github.com/vllm-project/vllm/issues/57719 gist.github.com: https://gist.github.com/Yunzez/5c70a3bb328eaf6d646b9d31e879dc4a#file-repro_prompt_embeds_penalties_engine_crash-py github.com: https://github.com/vllm-project/vllm/
Credits
๐ Zyz3366 (VulDB User) VulDB CNA Team