CVE-2026-93436 | vllm-project vLLM up to 0.29.0 Decode Worker Metadata Cleanup max_tokens resource consumption

SecurityVulns

A vulnerability categorized as problematic has been discovered in vllm-project vLLM up to 0.29.0. Affected is an unknown function of the component Decode Worker Metadata Cleanup. Executing a manipulation of the argument max_tokens can lead to resource consumption.

This vulnerability is handled as CVE-2026-93436. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More