vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
threat_severity
|
ssvc
|
Tue, 25 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests. | |
| Title | vLLM before 0.27.0 Denial of Service via DeepStream Backend | |
| First Time appeared |
Vllm
Vllm vllm |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vllm
Vllm vllm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-25T11:33:22.005Z
Updated: 2026-08-27T15:08:40.922Z
Reserved: 2026-08-25T01:17:12.263Z
Link: CVE-2026-78684
Updated: 2026-08-27T15:08:35.716Z
Status : Received
Published: 2026-08-25T12:16:27.387
Modified: 2026-08-27T17:20:43.657
Link: CVE-2026-78684