Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-93840

LOW NVD
CVSS Score 3.7
Severity LOW
Published Sep 18, 2026
Vendor unknown

Description

vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). Attackers can supply token IDs above the output vocabulary that pass validation, causing LogitBiasState to corrupt GPU logits state and allow concurrent requests to sample tokens outside their allowlists.

References