CVE-2026-90713 | vllm-project vLLM up to 0.29.0 tiktoken vocab File mod.rs TiktokenTokenizer::new denial of service (Issue 50954)

SecurityVulns

A vulnerability labeled as problematic has been found in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service.

This vulnerability is identified as CVE-2026-90713. The attack is only possible with local access. Additionally, an exploit exists.

The pull request to fix this issue awaits acceptance.VulDB Recent EntriesRead More