CVE-2026-56340: High-Risk Denial of Service Vulnerability in vLLM

CVE-2026-56340: High-Risk Denial of Service Vulnerability in vLLM

First seen 21 Jun 2026, 08:48 UTC Feedlyexploit-intel.comnitter.netvulners.com 89% similarity 70.5

Article Content

Browse articles
ThreatCluster

A critical vulnerability, CVE-2026-56340, affects vLLM versions 0.10.2 to 0.12.x, which lack sparse tensor validation in multimodal embeddings processing. Attackers can exploit this flaw by submitting malformed tensor indices to cause denial of service through crashes or resource exhaustion. The vulnerability could also lead to out-of-bounds memory corruption, potentially allowing arbitrary code execution. Currently, there is no public proof-of-concept or evidence of active exploitation. Users are advised to upgrade to vLLM version 0.13.0 or later, disable the prompt-embeds feature, and restrict network access to embedding endpoints. The CVSS score for this vulnerability is 8.8, indicating a high severity level. This issue follows CVE-2025-62164, which previously addressed related concerns but did not resolve the underlying problem.

Key Points: • CVE-2026-56340 affects vLLM versions 0.10.2 to 0.12.x, allowing denial of service attacks. • Attackers can exploit malformed tensor indices to trigger crashes and resource exhaustion. • Users are urged to upgrade to vLLM 0.13.0 or later to mitigate the risk.

ThreatCluster AI How this analysis works

Timeline

2025-11-21
CVE-2025-62164 published
CVE-2025-62164 was published, addressing issues in vLLM but not the root cause.
Feedly
2026-06-20
CVE-2026-56340 published
CVE-2026-56340 was published, detailing a denial of service vulnerability in vLLM.
Feedly
2026-06-21
Exploit Intelligence article published
Exploit Intelligence published details on CVE-2026-56340, emphasizing its high severity.
exploit-intel.com

Community

Browse all →

Tracked Entities in This Story