CVE-2026-100649 PUBLISHED

vLLM before 0.29.0 Resource Limit Bypass via Sampler Subclass

Assigner: VulnCheck
Reserved: 26.09.2026 Published: 26.09.2026 Updated: 26.09.2026

vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler subclass shadowing allows independent counter increments. Unauthenticated attackers can select different sampler subclasses in video requests to exceed configured decoder limits and exhaust unaccounted GPU memory.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.3

Product Status

Vendor vllm-project
Product vllm
Versions Default: unaffected
  • affected from 0 to 0.29.0 (excl.)
  • Version 0.29.0 is unaffected

Credits

  • JPengLi reporter
  • jperezdealgaba coordinator

References

Problem Types

  • Allocation of Resources Without Limits or Throttling CWE