VDB
Sign up
MEDIUM4.3

PYSEC-2026-4000

Quick fix

PYSEC-2026-4000 — vllm: upgrade to the fixed version with the command below.

pip install --upgrade 'vllm>=0.30.0'

Details

vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token indices that corrupt logits memory of concurrent requests, causing different in-flight HTTP requests to return incorrect tokens.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/vllm
Introduced in: 0Fixed in: 0.30.0
Fixpip install --upgrade 'vllm>=0.30.0'

References