CVE-2026-105922 | vllm-project vLLM up to 0.31.0 Penalty utils.py get_token_bin_counts_and_mask denial of service (Issue 57719)
A vulnerability classified as problematic has been found in vllm-project vLLM up to 0.31.0. This impacts the function get_token_bin_counts_and_mask of the file vllm/model_executor/layers/utils.py of the component Penalty Handler. Performing a manipulation results in denial of service.
This vulnerability is known as CVE-2026-105922. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More