Vulnerabilities & PatchesEmerging1 src
CVE-2026-93841 - vLLM through 0.29.0 Adjacent-Request Sampler State Corruption via Unvalidated Prompt Token IDs
CVE ID : CVE-2026-93841
Published : Sept. 18, 2026, 8:17 p. m.
• 38 minutes ago
Description : vLLM through 0. 29. 0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size.
Attackers can submit multimodal audio requests with tokens equal to vocabulary size, causing out-of-bounds writes that corrupt concurrent requests' sampler state and alter repetition penalty behavior.
Severity: 6.3
• MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...