CVE-2026-93989

Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
19/09/2026
Last modified:
28/09/2026

Description

vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token indices that corrupt logits memory of concurrent requests, causing different in-flight HTTP requests to return incorrect tokens.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:* 0.29.0 (including)