Description
A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 0.29.1rc0 is able to resolve this issue. This patch is called 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised.
Published: 2026-09-30
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Upgrade
AI Analysis

Impact

A flaw was identified in the Gemma4UnifiedParser component of vllm-project vLLM, specifically in the file rust/src/parser/src/unified/gemma4.rs. The vulnerability allows an attacker to execute crafted input that can cause the parser to enter an invalid state and crash, resulting in a denial of service condition for the affected service. The description notes that the exploit has already been published and may be used remotely.

Affected Systems

The vulnerability affects the vllm-project vLLM system. All releases up to version 0.26.0 are impacted because the faulty code resides in the Gemma4UnifiedParser. An upgrade to version 0.29.1rc0, which contains the patch identified as 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9, resolves the issue.

Risk and Exploitability

The CVSS score of 6.9 places this vulnerability in the moderate severity range, indicating a credible risk to availability. EPSS is not available, so the likelihood estimate is unknown, and the vulnerability is not listed in the CISA KEV catalog. The attack can be launched remotely by feeding malicious input to the parser; based on the description, the likely attack vector involves sending malformed data that triggers the denial of service. The exploit is already published, which means an adversary could readily mount the attack if an update is not applied.

Generated by OpenCVE AI on September 30, 2026 at 20:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update vllm to version 0.29.1rc0, which contains patch 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9.
  • Block external connections to the Gemma4UnifiedParser endpoint until the vendor releases a patched version or the system is updated, using firewall or access controls.
  • Implement monitoring for sudden increases in parser crashes or memory consumption, and alert on occurrences to ensure rapid response if the vulnerability is exploited before upgrades are completed.

Generated by OpenCVE AI on September 30, 2026 at 20:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 0.29.1rc0 is able to resolve this issue. This patch is called 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised.
Title vllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of service
First Time appeared Vllm-project
Vllm-project vllm
Weaknesses CWE-404
CPEs cpe:2.3:a:vllm-project:vllm:*:*:*:*:*:*:*:*
Vendors & Products Vllm-project
Vllm-project vllm
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Vllm-project Vllm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-02T16:23:50.737Z

Reserved: 2026-09-30T10:36:13.164Z

Link: CVE-2026-103241

cve-icon Vulnrichment

Updated: 2026-10-02T16:23:45.567Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-30T17:16:42.570

Modified: 2026-10-02T17:17:02.123

Link: CVE-2026-103241

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release