exploit-intel.com CVE-2026-56340: High-Risk Denial of Service Vulnerability in vLLM
Article Content
- •CVE-2026-56340 affects vLLM versions 0.10.2 to 0.12.x, allowing denial of service attacks.
- •Attackers can exploit malformed tensor indices to trigger crashes and resource exhaustion.
- •Users are urged to upgrade to vLLM 0.13.0 or later to mitigate the risk.
A critical vulnerability, CVE-2026-56340, affects vLLM versions 0.10.2 to 0.12.x, which lack sparse tensor validation in multimodal embeddings processing. Attackers can exploit this flaw by submitting malformed tensor indices to cause denial of service through crashes or resource exhaustion. The vulnerability could also lead to out-of-bounds memory corruption, potentially allowing arbitrary code execution. Currently, there is no public proof-of-concept or evidence of active exploitation. Users are advised to upgrade to vLLM version 0.13.0 or later, disable the prompt-embeds feature, and restrict network access to embedding endpoints. The CVSS score for this vulnerability is 8.8, indicating a high severity level. This issue follows CVE-2025-62164, which previously addressed related concerns but did not resolve the underlying problem.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2025-62164 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…