Loading market data...
← Back to CVE feed

CVE-2026-100649

LOW CVSS 3.7 View on NVD ↗

Description

vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler subclass shadowing allows independent counter increments. Unauthenticated attackers can select different sampler subclasses in video requests to exceed configured decoder limits and exhaust unaccounted GPU memory.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Published: Sep 26, 2026 14:16 UTC Modified: Sep 26, 2026 14:16 UTC