CVE-2026-105759

Published: Ott 06, 2026 Last Modified: Ott 06, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,9
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high

Description

AI Translation Available

vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the Rust frontend's track_http_metrics middleware records the raw HTTP method token as a Prometheus label for requests reaching registered routes. An unauthenticated attacker can send unique arbitrary method tokens to unguarded routes such as /tokenize, causing Prometheus's Family::get_or_create function to permanently create counter and histogram label sets. Those label sets increase process memory usage and enlarge the /metrics response until the service or monitoring path is exhausted. This issue is fixed in version 0.30.0.

400

Uncontrolled Resource Consumption

Draft
Common Consequences
Security Scopes Affected:
Availability Access Control Other
Potential Impacts:
Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory) Dos: Resource Consumption (Other) Bypass Protection Mechanism Other
Applicable Platforms
Technologies: Not Technology-Specific, AI/ML
View CWE Details
https://github.com/vllm-project/vllm/commit/3735c2d5f5248259482b9045c34fb7a8a38…
https://github.com/vllm-project/vllm/pull/56058
https://github.com/vllm-project/vllm/releases/tag/v0.30.0
https://github.com/vllm-project/vllm/security/advisories/GHSA-5fj9-pfhr-6j48