A critical vulnerability affecting vllm versions <= 0.23.0, CVE-2026-5497 with a CVSS score of 9.0, affects versions of the vllm package prior to 0.24.0, allowing an unauthenticated attacker to perform a remote denial-of-service attack via memory amplification on a default-no-auth endpoint impacting the availability of deployments serving audio-capable models. The flaw type is CWE-770 / CWE-409 and can be exploited through an unauthenticated reachability chain involving parse_input_audio, parse_audio, connector.fetch_audio, AudioMediaIO._load_data_url, load_base64, load_bytes, and load_audio. This vulnerability has a similar class and impact to CVE-2026-5497 (video) and is considered critical due to its potential for widespread disruption of audio-capable model deployments.
We recommend you to update vllm to version 0.24.0.[/subscribe_to_unlock_form]
A critical vulnerability affecting vllm versions <= 0.23.0, CVE-2026-5497 with a CVSS score of 9.0, affects versions of the vllm package prior to 0.24.0, allowing an unauthenticated attacker to perform a remote denial-of-service attack via memory amplification on a default-no-auth endpoint impacting the availability of deployments serving audio-capable models. The flaw type is CWE-770 / CWE-409 and can be exploited through an unauthenticated reachability chain involving parse_input_audio, parse_audio, connector.fetch_audio, AudioMediaIO._load_data_url, load_base64, load_bytes, and load_audio. This vulnerability has a similar class and impact to CVE-2026-5497 (video) and is considered critical due to its potential for widespread disruption of audio-capable model deployments.
We recommend you to update vllm to version 0.24.0.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]