CVE-2026-55514
EUVD-2026-4192506.07.2026, 21:16
vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with a model using M-RoPE causes EngineCore to fail an assertion and fatally crash, shutting down the entire server application. Any remote user who is authorized to make a /v1/completions request can make such a request and induce a crash. This issue is fixed in version 0.24.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vllm | vllm | 0.12.0 ≤ 𝑥 < 0.24.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration