Vulnerability Description
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation gates use comparison operators (<, >), which silently evaluate to False for NaN and for positive Infinity in Python's IEEE 754 float semantics. Both values pass every guard and propagate to GPU sampling kernels, where they produce undefined behavior or CUDA errors that can crash the inference worker. This vulnerability is fixed in 0.23.1rc0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vllm | Vllm | < 0.23.1 |
Related Weaknesses (CWE)
References
- https://github.com/vllm-project/vllm/commit/d598d239737cfa37bcfcb98886ec3f3557fcPatch
- https://github.com/vllm-project/vllm/pull/45116Issue Tracking
- https://github.com/vllm-project/vllm/security/advisories/GHSA-7h4p-rffg-7823ExploitThird Party Advisory
FAQ
What is CVE-2026-54235?
CVE-2026-54235 is a vulnerability with a CVSS score of 6.5 (MEDIUM). vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation gates use comparison operators (<, >), which silently evaluate to False for NaN ...
How severe is CVE-2026-54235?
CVE-2026-54235 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-54235?
Check the references section above for vendor advisories and patch information. Affected products include: Vllm Vllm.