CVE-2026-100654 | vllm-project vLLM up to 0.28.x EngineCore /v1/completions stop_token_ids input validation

SecurityVulns

A vulnerability identified as problematic has been detected in vllm-project vLLM up to 0.28.x. This vulnerability affects unknown code of the file /v1/completions of the component EngineCore. The manipulation of the argument stop_token_ids leads to improper input validation.

This vulnerability is traded as CVE-2026-100654. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More