Vulnerability Description
vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID triggers a CUDA device-side assertion that poisons the GPU context, causing all subsequent requests to fail until the process restarts.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/vllm-project/vllm/security/advisories/GHSA-25q3-v2hm-8vpf
- https://www.vulncheck.com/advisories/vllm-before-0.28.0-denial-of-service-via-ne
- https://github.com/vllm-project/vllm/security/advisories/GHSA-25q3-v2hm-8vpf
FAQ
What is CVE-2026-93592?
CVE-2026-93592 is a vulnerability with a CVSS score of 7.5 (HIGH). vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative to...
How severe is CVE-2026-93592?
CVE-2026-93592 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-93592?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.