Sceawere

Vulnerability Detail

CVE-2026-105922UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

vLLM Penalty Handler DoS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
10h ago
Vendor
vllm-project
Product
vLLM
Attack Type
Denial of Service
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in vllm-project vLLM up to 0.31.0. This impacts the function get_token_bin_counts_and_mask of the file vllm/model_executor/layers/utils.py of the component Penalty Handler. Performing a manipulation results in denial of service. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-06T15:17:17.727Z",
  "pubdate": "2026-10-06T15:17:17.727Z",
  "executiveSummary": "A critical denial of service (DoS) vulnerability exists in the Penalty Handler component of the vLLM project, specifically within the get_token_bin_counts_and_mask function located in vllm/model_executor/layers/utils.py.\nThe vulnerability affects all versions of vLLM up to and including 0.31.0. The flaw allows remote, unauthenticated attackers to trigger a system crash or resource exhaustion by providing specifically crafted inputs.\nAs the exploit is publicly available and the maintainers have not yet provided a patch, there is a significant risk of active exploitation. Successful utilization of this vulnerability leads to service disruption, impacting the availability of LLM inference services relying on the affected codebase.\nThere are no requirements for local access or pre-existing privileges, making this a high-risk remote attack vector. Organizations utilizing affected versions of vLLM are advised to implement immediate defensive measures to protect their inference infrastructure.",
  "technicalDetails": "The vulnerability originates in the get_token_bin_counts_and_mask function within vllm/model_executor/layers/utils.py, which is responsible for processing penalty logic during token generation in the vLLM model execution pipeline.\nThe root cause appears to be improper input validation or boundary checking during the manipulation of token bin counts. When the function receives maliciously crafted input tensors or parameters that deviate from expected distribution or range constraints, it leads to an exception or out-of-bounds memory access that the application does not gracefully handle.\nThe attack flow involves an adversary submitting an inference request to the vLLM API endpoint containing a payload specifically engineered to trigger the flaw within the penalty handler logic. Because the penalty handler processes these inputs as part of the standard autoregressive generation process, the malicious input is processed immediately upon receipt.\nUpon execution, the flawed logic triggers a fatal error—likely an unhandled exception or a panic within the Python runtime or the underlying PyTorch/CUDA operations—resulting in the immediate termination of the worker process or the entire model server instance.\nThis vulnerability is classified as remote because the vLLM service, typically exposed via an API server, will process the untrusted input directly from the network request. No authentication or elevated privileges are required to reach the vulnerable code path.\nThe impact of a successful exploit is a denial of service. By repeatedly sending the malicious payload, an attacker can ensure persistent downtime of the model inference service, effectively preventing legitimate users from accessing the LLM capabilities.\nSince the exploit code is already in the public domain, the barrier to entry for attackers is low. The lack of an official patch exacerbates the risk, as automated exploitation or scanning for this vulnerability is likely occurring in the wild against publicly accessible vLLM instances."
}
CVE-2026-105922: vLLM Penalty Handler DoS Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere