CVE-2026-55514

MEDIUM

vLLM denial of service via prompt embeds on M-RoPE models

Title source: cna
STIX 2.1

Description

vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with a model using M-RoPE causes EngineCore to fail an assertion and fatally crash, shutting down the entire server application. Any remote user who is authorized to make a /v1/completions request can make such a request and induce a crash. This issue is fixed in version 0.24.0.

Scores

CVSS v3 6.5
EPSS 0.0037
EPSS Percentile 29.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-617
Status published
Products (3)
pypi/vllm 0.12.0 - 0.24.0PyPI
vllm/vllm 0.12.0 - 0.24.0
vllm-project/vllm >= 0.12.0, < 0.24.0
Published Jul 06, 2026
Tracked Since Jul 07, 2026