CVE-2026-90555 PUBLISHED

vLLM before 0.28.0 Denial of Service via Audio Header

Assigner: VulnCheck
Reserved: 12.09.2026 Published: 12.09.2026 Updated: 12.09.2026

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor vllm-project
Product vLLM
Versions Default: unaffected
  • affected from 0 to 0.28.0 (excl.)
  • Version 0.28.0 is unaffected

Credits

  • oran-s reporter
  • jperezdealgaba coordinator

References

Problem Types

  • Improper Handling of Highly Compressed Data (Data Amplification) CWE