MEDIUM
CVE-2026-90555
CVSS
6.5
Description
vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.
Weakness (CWE)
CWE-409
EPSS Score
0.29%
Probability of exploitation in next 30 days
22.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.