Reliance on Untrusted Inputs in a Security Decision in vLLM - #VU146572
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to reliance on untrusted inputs in a security decision in the /v1/audio/transcriptions audio decoding path when processing a crafted audio file with a forged header sample rate. A remote user can submit a specially crafted FLAC file to cause a denial of service.
Exploitation requires a valid API key and a transcription-capable model with the /v1/audio/* endpoint mounted.