Allocation of Resources Without Limits or Throttling Affecting vllm package, versions [0.7.0,0.19.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-VLLM-15907609
  • published5 Apr 2026
  • disclosed3 Apr 2026
  • creditSeokjun Ryu

Introduced: 3 Apr 2026

NewCVE-2026-34755  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade vllm to version 0.19.0 or higher.

Overview

vllm is an A high-throughput and memory-efficient inference and serving engine for LLMs

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling due to the lack of a frame count limit in the load_base64 function when processing video/jpeg base64 data. An attacker can exhaust system memory and cause a server crash by submitting a request containing a large number of comma-separated base64-encoded JPEG frames.

CVSS Base Scores

version 4.0
version 3.1