Impact
A flaw was identified in the Gemma4UnifiedParser component of vllm-project vLLM, specifically in the file rust/src/parser/src/unified/gemma4.rs. The vulnerability allows an attacker to execute crafted input that can cause the parser to enter an invalid state and crash, resulting in a denial of service condition for the affected service. The description notes that the exploit has already been published and may be used remotely.
Affected Systems
The vulnerability affects the vllm-project vLLM system. All releases up to version 0.26.0 are impacted because the faulty code resides in the Gemma4UnifiedParser. An upgrade to version 0.29.1rc0, which contains the patch identified as 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9, resolves the issue.
Risk and Exploitability
The CVSS score of 6.9 places this vulnerability in the moderate severity range, indicating a credible risk to availability. EPSS is not available, so the likelihood estimate is unknown, and the vulnerability is not listed in the CISA KEV catalog. The attack can be launched remotely by feeding malicious input to the parser; based on the description, the likely attack vector involves sending malformed data that triggers the denial of service. The exploit is already published, which means an adversary could readily mount the attack if an update is not applied.
OpenCVE Enrichment