← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 18, 2026 · 20:17via CVEFeed

CVE-2026-93841 - vLLM through 0.29.0 Adjacent-Request Sampler State Corruption via Unvalidated Prompt Token IDs

Brief

CVE ID : CVE-2026-93841

Published : Sept. 18, 2026, 8:17 p. m.

  • 38 minutes ago

Description : vLLM through 0.

  • 0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size.

Attackers can submit multimodal audio requests with tokens equal to vocabulary size, causing out-of-bounds writes that corrupt concurrent requests' sampler state and alter repetition penalty behavior.

Severity: 6.3

  • MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed→