Threat Advisory

vLLM Lets Attackers Allocate Unbounded Memory via Oversized Multipart Upload

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting vllm versions Confirmed on vLLM 0 affecting vllm versions >= 0 affecting vllm versions Validated against current head: have been identified in vllm. The overall risk/impact is moderate to high, with affected versions ranging from 0.22.0 to less than 0.24.0.

CVE-2026-54234: A remote denial-of-service vulnerability exists via invalid recovered token reinjection in vllm's speech-to-text APIs. An attacker can submit an oversized audio file, causing vllm to allocate memory proportional to the uploaded file size before rejecting the request.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting vllm versions Confirmed on vLLM 0 affecting vllm versions >= 0 affecting vllm versions Validated against current head: have been identified in vllm. The overall risk/impact is moderate to high, with affected versions ranging from 0.22.0 to less than 0.24.0.

CVE-2026-54234: A remote denial-of-service vulnerability exists via invalid recovered token reinjection in vllm's speech-to-text APIs. An attacker can submit an oversized audio file, causing vllm to allocate memory proportional to the uploaded file size before rejecting the request.[emaillocker id="1283"]

CVE-2026-55646: This is not a claim of code execution, data access, cross-tenant data exposure, parser-level multipart memory exhaustion, or persistence after process restart. Deployment body-size limits at a reverse proxy or ASGI layer can mitigate the issue before vllm sees the request.

CVE-2026-55574: The impact is availability-only. This vulnerability does not appear to be intended behavior and vLLM's security guide treats request-controlled resource use as a security boundary.

CVE-2026-34760: An API caller who meets certain requirements can send an oversized audio file, causing vllm to read the full uploaded file into memory before applying the configured compressed audio file-size limit. This can create memory pressure or terminate the process before the request is rejected.

These vulnerabilities collectively present a moderate to high risk, primarily affecting deployments that expose speech-to-text capabilities and allow API callers to submit requests. Administrators should review exposure and apply updates accordingly.

RECOMMENDATION:

We recommend you to update vllm to version 0.24.0.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu