Impact
vLLM versions prior to validate the sample rate in FLAC audio headers used by the transcription endpoint. This missing check allows an authenticated user to craft a header with an inflated sample rate, causing the server to allocate an excessive amount of memory during transcription. The resulting memory exhaustion triggers a crash of the API server, leading to a denial of service that impacts all tenants that rely on the service.
Affected Systems
Any deployment of the open‑source library vLLM from vllm-project using a 0.28.0‑older release is susceptible to this flaw, as identified in the advisory.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated client that submits a specially crafted FLAC file. Successful service interruption for all tenants. Attackers with valid credentials can therefore achieve widespread denial of service with minimal effort once an account is compromised.
OpenCVE Enrichment