LOW 2.3 NVD
CVE-2026-93989
vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). At
vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token indices that corrupt logits memory of concurrent requests, causing different in-flight HTTP requests to return incorrect tokens.
References
- https://github.com/vllm-project/vllm
- https://github.com/vllm-project/vllm/blob/98dff2a81d747d1dba01a47f939f48c3526d4206/vllm/sa
- https://github.com/vllm-project/vllm/blob/98dff2a81d747d1dba01a47f939f48c3526d4206/vllm/v1
- https://github.com/vllm-project/vllm/pull/48824
- https://www.vulncheck.com/advisories/vllm-through-0.29.0-cross-request-logits-corruption-v
This low severity vulnerability with a CVSS score of 2.3 was published on 2026-09-19 via NVD.
vulnfeed aggregates 14150 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.