CVE-2026-100654 | vllm-project vLLM up to 0.28.x EngineCore /v1/completions stop_token_ids input validation
A vulnerability identified as problematic has been detected in vllm-project vLLM up to 0.28.x. This vulnerability affects unknown code of the file /v1/completions of the component EngineCore. The manipulation of the argument stop_token_ids leads to improper input validation.
This vulnerability is traded as CVE-2026-100654. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More