—
PYSEC-2026-3996
Quick fix
PYSEC-2026-3996 — vllm: upgrade to the fixed version with the command below.
pip install --upgrade 'vllm>=0.30.0'Details
vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 to exhaust decode-worker memory without bound until the worker restarts.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/vllm-project/vllm/blob/v0.29.0/vllm/distributed/kv_transfer/kv_connector/v1/nixl/push_worker.py#L162-L181[WEB]
- https://www.vulncheck.com/advisories/vllm-through-0.29.0-memory-exhaustion-via-rejected-requests[ADVISORY]
- https://github.com/vllm-project/vllm/pull/55677[FIX]
- https://github.com/vllm-project/vllm[PACKAGE]