Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-54233

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcriptions endpoint limits compressed upload size but not decoded PCM output. A 25MB OPUS file expands to ~14.9GB of float32 PCM at decode time. This vulnerability is fixed in 0.23.1rc0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 15.3%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-54233
  • Vllm » Vllm » Version: 0.10.0
    cpe:2.3:a:vllm:vllm:0.10.0
  • Vllm » Vllm » Version: 0.10.1
    cpe:2.3:a:vllm:vllm:0.10.1
  • Vllm » Vllm » Version: 0.10.2
    cpe:2.3:a:vllm:vllm:0.10.2
  • Vllm » Vllm » Version: 0.11.0
    cpe:2.3:a:vllm:vllm:0.11.0
  • Vllm » Vllm » Version: 0.11.1
    cpe:2.3:a:vllm:vllm:0.11.1
  • Vllm » Vllm » Version: 0.13.0
    cpe:2.3:a:vllm:vllm:0.13.0
  • Vllm » Vllm » Version: 0.14.0
    cpe:2.3:a:vllm:vllm:0.14.0
  • Vllm » Vllm » Version: 0.15.0
    cpe:2.3:a:vllm:vllm:0.15.0
  • Vllm » Vllm » Version: 0.15.1
    cpe:2.3:a:vllm:vllm:0.15.1
  • Vllm » Vllm » Version: 0.16.0
    cpe:2.3:a:vllm:vllm:0.16.0
  • Vllm » Vllm » Version: 0.17.0
    cpe:2.3:a:vllm:vllm:0.17.0
  • Vllm » Vllm » Version: 0.17.1
    cpe:2.3:a:vllm:vllm:0.17.1
  • Vllm » Vllm » Version: 0.18.0
    cpe:2.3:a:vllm:vllm:0.18.0
  • Vllm » Vllm » Version: 0.18.1
    cpe:2.3:a:vllm:vllm:0.18.1
  • Vllm » Vllm » Version: 0.19.0
    cpe:2.3:a:vllm:vllm:0.19.0
  • Vllm » Vllm » Version: 0.19.1
    cpe:2.3:a:vllm:vllm:0.19.1
  • Vllm » Vllm » Version: 0.2.1
    cpe:2.3:a:vllm:vllm:0.2.1
  • Vllm » Vllm » Version: 0.20.0
    cpe:2.3:a:vllm:vllm:0.20.0
  • Vllm » Vllm » Version: 0.20.1
    cpe:2.3:a:vllm:vllm:0.20.1
  • Vllm » Vllm » Version: 0.20.2
    cpe:2.3:a:vllm:vllm:0.20.2
  • Vllm » Vllm » Version: 0.21.0
    cpe:2.3:a:vllm:vllm:0.21.0
  • Vllm » Vllm » Version: 0.21.1
    cpe:2.3:a:vllm:vllm:0.21.1
  • Vllm » Vllm » Version: 0.22.0
    cpe:2.3:a:vllm:vllm:0.22.0
  • Vllm » Vllm » Version: 0.22.1
    cpe:2.3:a:vllm:vllm:0.22.1
  • Vllm » Vllm » Version: 0.23.0
    cpe:2.3:a:vllm:vllm:0.23.0
  • Vllm » Vllm » Version: 0.4.0
    cpe:2.3:a:vllm:vllm:0.4.0
  • Vllm » Vllm » Version: 0.5.0
    cpe:2.3:a:vllm:vllm:0.5.0
  • Vllm » Vllm » Version: 0.5.3
    cpe:2.3:a:vllm:vllm:0.5.3
  • Vllm » Vllm » Version: 0.6.1
    cpe:2.3:a:vllm:vllm:0.6.1
  • Vllm » Vllm » Version: 0.6.3
    cpe:2.3:a:vllm:vllm:0.6.3
  • Vllm » Vllm » Version: 0.6.4
    cpe:2.3:a:vllm:vllm:0.6.4
  • Vllm » Vllm » Version: 0.6.6
    cpe:2.3:a:vllm:vllm:0.6.6
  • Vllm » Vllm » Version: 0.8.0
    cpe:2.3:a:vllm:vllm:0.8.0
  • Vllm » Vllm » Version: 0.8.3
    cpe:2.3:a:vllm:vllm:0.8.3
  • Vllm » Vllm » Version: 0.8.5
    cpe:2.3:a:vllm:vllm:0.8.5
  • Vllm » Vllm » Version: 0.9.1
    cpe:2.3:a:vllm:vllm:0.9.1
  • Vllm » Vllm » Version: 0.9.2
    cpe:2.3:a:vllm:vllm:0.9.2


Contact Us

Shodan ® - All rights reserved