Vulnerability Description
vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vllm | Vllm | < 0.28.0 |
Related Weaknesses (CWE)
References
- https://github.com/vllm-project/vllm/security/advisories/GHSA-99f2-hwrc-gvq8Vendor Advisory
- https://www.vulncheck.com/advisories/vllm-before-0.28.0-denial-of-service-via-auThird Party Advisory
FAQ
What is CVE-2026-90555?
CVE-2026-90555 is a vulnerability with a CVSS score of 6.5 (MEDIUM). vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers...
How severe is CVE-2026-90555?
CVE-2026-90555 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-90555?
Check the references section above for vendor advisories and patch information. Affected products include: Vllm Vllm.