CVE-2026-105759: Vllm-Project Vllm
Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the Rust frontend's track_http_metrics middleware records the raw HTTP method token as a Prometheus label for requests reaching registered routes. An unauthenticated attacker can send unique arbitrary method tokens to unguarded routes such as /tokenize, causing Prometheus's Family::get_or_create function to permanently create counter and histogram label sets. Those label sets increase process memory usage and enlarge the /metrics response until the service or monitoring path is exhausted. This issue is fixed in version 0.30.0.
Affected products
- Vllm-Project Vllm: before 0.30.0 (fixed in 0.30.0)
Published 2026-10-05. Last modified 2026-10-06.