Resource exhaustion in vLLM - CVE-2026-69147
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the video decoding path when processing video requests with a request-selected PyNvVideoCodec backend. A remote user can send a specially crafted video request to cause a denial of service.
Exploitation requires a GPU deployment where PyNvVideoCodec is installed and usable, and the request must reach a video-capable model or path.