CVE-2026-93840 | vllm-project vLLM up to 0.28.x SamplingParams._validate_allowed_token_ids input validation

SecurityVulns

A vulnerability was found in vllm-project vLLM up to 0.28.x and classified as critical. This issue affects the function SamplingParams._validate_allowed_token_ids. The manipulation results in improper input validation.

This vulnerability is identified as CVE-2026-93840. The attack can be executed remotely. There is not any exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More