Description
A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Awaited
AI Analysis

Impact

A flaw in the TiktokenTokenizer::new function of vllm-project vLLM allows a local attacker to manipulate the tiktoken vocabulary file and trigger a denial of service. The CVE description notes that the vulnerability results from improper handling and can be exploited only with local access, and the public exploit has already been released.

Affected Systems

vllm-project vLLM releases up to version 0.29.0 are impacted; no other vendors or products are listed as affected.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate impact potential, while the EPSS score of less than 1 % suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local access to the system running vLLM and can be performed using the publicly available exploit; the pending pull request to fix the issue has not yet been merged.

Generated by OpenCVE AI on September 21, 2026 at 01:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Await the acceptance of Pull Request 51135 and upgrade vLLM to the patched version once it becomes available.
  • If an upgrade cannot be performed immediately, restrict local execution of TiktokenTokenizer::new by limiting file‑system access to the vocabulary file and running the tokenizer in a sandboxed environment to prevent tampering.
  • Implement runtime resource limits or enforce timeouts on the tokenizer routine to mitigate potential resource exhaustion until an official fix is released.

Generated by OpenCVE AI on September 21, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

threat_severity

Low


Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.
Title vllm-project vLLM tiktoken vocab File mod.rs new denial of service
First Time appeared Vllm-project
Vllm-project vllm
Weaknesses CWE-404
CPEs cpe:2.3:a:vllm-project:vllm:*:*:*:*:*:*:*:*
Vendors & Products Vllm-project
Vllm-project vllm
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Vllm-project Vllm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:57:19.501Z

Reserved: 2026-09-13T09:40:58.177Z

Link: CVE-2026-90713

cve-icon Vulnrichment

Updated: 2026-09-15T13:42:12.418Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T13:19:29.677

Modified: 2026-09-15T14:17:33.490

Link: CVE-2026-90713

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-14T12:00:10Z

Links: CVE-2026-90713 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:30:08Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-770

    Allocation of Resources Without Limits or Throttling