Impact
The vulnerability lies in the thinking_budget_state.py module of the vllm project, allowing an attacker to trigger a computationally expensive routine. This inefficient algorithmic complexity can consume excessive CPU cycles when invoked, leading to a denial of service for legitimate users. The weakness is captured by CWE‑404, CWE‑407 and CWE‑770, indicating improper handling of internal state, resource exhaustion and unchecked complexity.
Affected Systems
vllm‑project vllm versions up to 0.29.0 are affected. The flaw is present in the vllm/v1/sample/thinking_budget_state.py file and any deployment that imports or utilizes this module remains vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of <1% suggests the likelihood of exploitation is very low at present, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack vector is remote; any user capable of interacting with the exposed functionality can trigger the costly algorithm. Once exploited, the attacker could stall or crash the service by forcing prolonged CPU usage.
OpenCVE Enrichment