OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-100648

MEDIUM · CVSS 5.3 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability in vllm prior to version 0.29.0 allows unauthenticated clients to bypass file size restrictions on audio files during multimodal chat audio decoding, leading to potential resource exhaustion. Attackers can exploit this flaw by submitting oversized audio files, which may result in excessive memory and CPU consumption. Organizations utilizing vllm for chat functionalities should prioritize patching to mitigate the risk of denial-of-service attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100648
Severity
MEDIUM
CVSS
5.3
EPSS
0.33%

Original NVD Description

vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing unauthenticated clients to bypass file size restrictions. Attackers can submit oversized audio files through chat endpoints to consume excessive memory and CPU resources during decoding.

Related CVEs

Other vulnerabilities affecting the same vendor(s)