Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-93592

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID triggers a CUDA device-side assertion that poisons the GPU context, causing all subsequent requests to fail until the process restarts.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 31.6%
CVSS Severity
CVSS v3 Score 7.5


Contact Us

Shodan ® - All rights reserved