exploit-intel.com
CVE-2026-56340: High-Risk Denial of Service Vulnerability in vLLM
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability, CVE-2026-56340, affects vLLM versions 0.10.2 to 0.12.x, which lack sparse tensor validation in multimodal embeddings processing. Attackers can exploit this flaw by submitting malformed tensor indices to cause denial of service through crashes or resource exhaustion. The vulnerability could also lead to out-of-bounds memory corruption, potentially allowing arbitrary code execution. Currently, there is no public proof-of-concept or evidence of active exploitation. Users are advised to upgrade to vLLM version 0.13.0 or later, disable the prompt-embeds feature, and restrict network access to embedding endpoints. The CVSS score for this vulnerability is 8.8, indicating a high severity level. This issue follows CVE-2025-62164, which previously addressed related concerns but did not resolve the underlying problem.
Key Points: • CVE-2026-56340 affects vLLM versions 0.10.2 to 0.12.x, allowing denial of service attacks. • Attackers can exploit malformed tensor indices to trigger crashes and resource exhaustion. • Users are urged to upgrade to vLLM 0.13.0 or later to mitigate the risk.