SEPTEMBER 29, 2026
Live Feed
Back to database
Case File

CVE-2026-93840

LOW · CVSS 3.7 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-09-29

CyberRota Analysis

AI-Generated

The vulnerability affects vLLM versions prior to 0.29.0, where improper validation of allowed token IDs can lead to the corruption of GPU logits state. This flaw allows attackers to bypass token restrictions, potentially enabling them to sample unauthorized tokens in concurrent requests. Organizations using affected versions of vLLM should prioritize patching to mitigate the risk of unauthorized access and data leakage.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-93840
Severity
LOW
CVSS
3.7
EPSS
N/A

Original NVD Description

vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). Attackers can supply token IDs above the output vocabulary that pass validation, causing LogitBiasState to corrupt GPU logits state and allow concurrent requests to sample tokens outside their allowlists.

Related CVEs

Other vulnerabilities affecting the same vendor(s)