SEPTEMBER 29, 2026
Live Feed
Back to database
Case File

CVE-2026-93989

LOW · CVSS 3.1 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-19 · Last synced 2026-09-29

CyberRota Analysis

AI-Generated

vLLM versions up to 0.29.0 are vulnerable due to improper validation of bad_words token indices, allowing attackers to exploit out-of-bounds indices that can corrupt the logits memory during concurrent requests. This can lead to incorrect token outputs for different in-flight HTTP requests, potentially compromising data integrity. Organizations using vLLM should prioritize this vulnerability to mitigate risks associated with incorrect model outputs.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-93989
Severity
LOW
CVSS
3.1
EPSS
N/A

Original NVD Description

vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token indices that corrupt logits memory of concurrent requests, causing different in-flight HTTP requests to return incorrect tokens.

Related CVEs

Other vulnerabilities affecting the same vendor(s)