๐Ÿ” CVE Alert

CVE-2026-105922

MEDIUM 4.3

vllm-project vLLM Penalty utils.py get_token_bin_counts_and_mask denial of service

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A security flaw has been discovered in vllm-project vLLM up to 0.31.0. This impacts the function get_token_bin_counts_and_mask of the file vllm/model_executor/layers/utils.py of the component Penalty Handler. Performing a manipulation results in denial of service. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CWE CWE-404
Vendor vllm-project
Product vllm
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for vllm-project vllm

Be the first to know when new medium vulnerabilities affecting vllm-project vllm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

vllm-project / vLLM
0.1 0.2 0.3 0.4 0.5 0.6 0.7 0.8 0.9 0.10 0.11 0.12 0.13 0.14 0.15 0.16 0.17 0.18 0.19 0.20 0.21 0.22 0.23 0.24 0.25 0.26 0.27 0.28 0.29 0.30 0.31.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/413896 vuldb.com: https://vuldb.com/vuln/413896/cti vuldb.com: https://vuldb.com/cve/CVE-2026-105922 vuldb.com: https://vuldb.com/submit/992707 github.com: https://github.com/vllm-project/vllm/issues/57719 gist.github.com: https://gist.github.com/Yunzez/5c70a3bb328eaf6d646b9d31e879dc4a#file-repro_prompt_embeds_penalties_engine_crash-py github.com: https://github.com/vllm-project/vllm/

Credits

๐Ÿ” Zyz3366 (VulDB User) VulDB CNA Team