MEDIUMCVSS 6.5Vulnerability

CVE-2026-73559

vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in vllm/entrypoints/openai/completion/protocol.py accepts an unbounded list[str] or list[list[int]], prompt_to_seq() in vllm/renderers/inputs/preprocess.py and OnlineRenderer.preprocess_completion() in vllm/renderers/online_renderer.py expand every element, and vllm/entrypoints/openai/completion/serving.py creates one engine generator and response slot per prompt, allowing an authenticated API client to exhaust CPU, memory, async scheduling capacity, engine request slots, and response buffering with one request. This issue is fixed in version 0.26.0.

Properties

summary
vLLM: Completion prompt lists fan out into unbounded engine requests
severity
MEDIUM
cvss_severity
MEDIUM
epss_score
0.00548
cvss_score
6.5
retrieved_at
2026-09-27T13:53:59+00:00
ghsa_published
2026-08-13T18:40:06Z
source_url
https://github.com/advisories/GHSA-87x5-vmc3-756j
ghsa_updated
2026-08-13T18:40:09Z
ghsa_id
GHSA-87x5-vmc3-756j
last_source
FIRST EPSS
score
6.5
cve_id
CVE-2026-73559
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-11T17:54:58+00:00
is_ghsa_only
false
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
published_at
2026-08-13T16:19:05.863
last_modified
2026-09-09T20:58:37.713
epss_percentile
0.43662

Related Entities (6)

DESCRIBED_BY (1)

→[Source]NVD

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]pip/vllm

AFFECTS (1)

→[Software]pip/vllm

HAS_WEAKNESS (1)

→[Weakness]Uncontrolled Resource Consumption

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73559 (CVSS 6.5) — Ninja Signal Threat Intelligence | Ninja Signal