Input validation error in vLLM - #VU139881

 

Input validation error in vLLM - #VU139881

Published: July 28, 2026


Vulnerability identifier: #VU139881
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to alter downstream model reasoning.

The vulnerability exists due to improper input validation in the image loading logic in vllm/multimodal/image.py when parsing APNG or GIF files. A remote attacker can supply a specially crafted image to alter downstream model reasoning.

Only the first frame is loaded when processing APNG or GIF images.


Affected software

vLLM

Remediation

Install security update from vendor's website.

vLLM - update to 0.24.0

External References

Related Security Bulletins