MEDIUMVulnerability

CVE-2026-90555

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-90555
signal_observed_at
2026-09-21T23:07:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
published_at
2026-09-12T13:16:54.180
last_modified
2026-09-16T17:31:06.907

Related Entities (3)

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Improper Handling of Highly Compressed Data (Data Amplification)

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90555 — Ninja Signal Threat Intelligence | Ninja Signal