VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-93592

CVE-2026-93592: vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints,

Published Sep 18, 2026 CVSS 8.7

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID triggers a CUDA device-side assertion that poisons the GPU context, causing all subsequent requests to fail until the process restarts.

Affected AI Products

vllm
Get the weekly digest. Every Monday: top AI security stories of the week. Free.