CVE-2026-90555
vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-409
- Published
- 2026-09-12
- Last modified
- 2026-09-14
Affected products
- vllm-project vLLM
- vllm-project vLLM
Weakness type
Related vulnerabilities
- CVE-2025-66471 — urllib3 Streaming API improperly handles highly compressed data
- CVE-2026-22776 — cpp-httplib vulnerable to a denial of service (DOS) using a zip bomb
- CVE-2026-5132 — Unbounded zlib decompression in Calls SDP WebSocket messages
- CVE-2026-15814 — Uploading a crafted image causes excessive memory allocation in the Mattermost Server
- CVE-2026-14298 — Boards archive import endpoint allows resource exhaustion via zip bomb and file size limit bypass in Mattermost
- CVE-2026-10819 — Mattermost Server Denial of Service via Animated GIF Emoji Upload
- CVE-2026-21441 — urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
- CVE-2024-7765 — Denial of Service in h2oai/h2o-3