Vulnerability record · CVE-2026-93592 · published 18 September 2026
CVE-2026-93592: Vllm vulnerability
Vllm · Vllm
vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID triggers a CUDA device-side assertion that poisons the GPU context, causing all subsequent requests to fail until the process restarts.
Description
vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID triggers a CUDA device-side assertion that poisons the GPU context, causing all subsequent requests to fail until the process restarts.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/vllm-project/vllm/security/advisories/GHSA-25q3-v2hm-8vpf | ExploitMitigationPatchVendor Advisory |
| https://www.vulncheck.com/advisories/vllm-before-0.28.0-denial-of-service-via-negative-token-id | Third Party Advisory |
| https://github.com/vllm-project/vllm/security/advisories/GHSA-25q3-v2hm-8vpf | ExploitMitigationPatchVendor Advisory |
Track CVE-2026-93592 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-93592), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.