CVE-2026-54233
MEDIUMvLLM: OOM Denial of Service via Audio Decompression Bomb
Title source: cnaDescription
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcriptions endpoint limits compressed upload size but not decoded PCM output. A 25MB OPUS file expands to ~14.9GB of float32 PCM at decode time. This vulnerability is fixed in 0.23.1rc0.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/vllm-project/vllm/security/advisories/GHSA-6pr9-rp53-2pmc
X_Refsource_Misc x_refsource_misc
https://github.com/vllm-project/vllm/pull/44970
Scores
CVSS v3
6.5
EPSS
0.0042
EPSS Percentile
34.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-409
Status
published
Products (3)
pypi/vllm
0 - 0.24.0PyPI
vllm/vllm
< 0.23.1
vllm-project/vllm
< 0.23.1rc0
Published
Jun 22, 2026
Tracked Since
Jun 23, 2026