Description
A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Remote Data Exposure
Action: Monitor
AI Analysis

Impact

An out‑of‑bounds read vulnerability has been identified in vllm-project vLLM. The flaw resides in the conv_ssm_forward function of the mamba_mixer2.py file within the Completions Request Handler. The vulnerability permits an attacker to read memory beyond the intended bounds, potentially exposing sensitive data. The CVSS score of 5.3 indicates a moderate impact, and the exploit type is remote. The description explicitly states that the attack is feasible from a remote context and that the exploit is publicly disclosed.

Affected Systems

vllm‑project vLLM versions up to and including 0.31.0 are affected. Early versions prior to 0.31.0 are not listed as impacted.

Risk and Exploitability

The vulnerability carries a moderate CVSS score of 5.3 but is not currently listed in the CISA KEV catalog. Exploit probability information has not been provided. Because the flaw allows only out‑of‑bounds read, it does not enable arbitrary code execution; however, the remote nature of the attack and lack of mitigation make the vulnerability a usable vector for data leakage until a patch is released.

Generated by OpenCVE AI on October 6, 2026 at 07:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vLLM to the latest released version once the vendor provides a patch that removes the out‑of‑bounds read in conv_ssm_forward.
  • Disable or tightly restrict remote access to the Completions Request Handler endpoint until an official fix is available.
  • Monitor the vLLM GitHub repository and security advisories for an update; if a patch is delayed, apply a temporary code change that adds explicit bounds checks to the conv_ssm_forward implementation.

Generated by OpenCVE AI on October 6, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 06:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title vllm-project vLLM Completions Request mamba_mixer2.py conv_ssm_forward out-of-bounds
First Time appeared Vllm-project
Vllm-project vllm
Weaknesses CWE-119
CWE-125
CPEs cpe:2.3:a:vllm-project:vllm:*:*:*:*:*:*:*:*
Vendors & Products Vllm-project
Vllm-project vllm
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Vllm-project Vllm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-06T05:45:11.082Z

Reserved: 2026-10-05T20:26:34.831Z

Link: CVE-2026-105775

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T06:17:00.280

Modified: 2026-10-06T06:17:00.280

Link: CVE-2026-105775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T07:30:19Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-125

    Out-of-bounds Read