Description
vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). Attackers can supply token IDs above the output vocabulary that pass validation, causing LogitBiasState to corrupt GPU logits state and allow concurrent requests to sample tokens outside their allowlists.
Published: 2026-09-18
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unintended token sampling and potential data leakage between requests
Action: Update vLLM
AI Analysis

Impact

vLLM before 0.29.0 contains a validation flaw in SamplingParams._validate_allowed_token_ids that checks the length of allowed_token_ids against the tokenizer length instead of the model output logits width. The flaw allows attackers to supply token IDs that exceed the model’s vocabulary size, which pass validation but corrupt the GPU logits state via LogitBiasState. This corruption enables concurrent requests to sample tokens that lie outside their intended allowlists, potentially revealing data or behaving unpredictably. The weakness is a classic example of CWE‑129, an “Improper Validation of Array Index” scenario, and also introduces a memory corruption issue (CWE-787) by writing beyond array bounds during logits processing.

Affected Systems

The vulnerability affects the vLLM project’s vLLM product on all releases earlier than version 0.29.0. Users running any vLLM instance built from source or installed from packaging before the 0.29.0 release are susceptible, regardless of the deployment environment.

Risk and Exploitability

The CVSS score of 6.3 places the issue in the moderate severity range. The EPSS score of less than 1 % indicates a very low probability of exploitation in the near term, and the vulnerability is not listed in CISA’s KEV catalog. Likely attack vectors involve an attacker with network access to a vLLM server sending crafted requests that set allowed_token_ids beyond the logits width; no privileged or local execution is required. This scenario suggests the risk is moderate but the actual likelihood of exploitation remains low under normal exposure conditions.

Generated by OpenCVE AI on September 23, 2026 at 01:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to vLLM 0.29.0 or later where the allowed_token_ids validation has been corrected
  • If an upgrade is not immediately possible, manually verify that any allowed_token_ids used in SamplingParams are truncated to the model’s actual vocabulary size before sending requests
  • Disable or limit the use of LogitBiasState and custom token allowlists if they are not essential to the application

Generated by OpenCVE AI on September 23, 2026 at 01:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). Attackers can supply token IDs above the output vocabulary that pass validation, causing LogitBiasState to corrupt GPU logits state and allow concurrent requests to sample tokens outside their allowlists.
Title vLLM before 0.29.0 Cross-Request Logits Corruption via allowed_token_ids
First Time appeared Vllm
Vllm vllm
Weaknesses CWE-129
CPEs cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*
Vendors & Products Vllm
Vllm vllm
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:23:15.056Z

Reserved: 2026-09-18T18:16:47.489Z

Link: CVE-2026-93840

cve-icon Vulnrichment

Updated: 2026-09-21T18:29:57.171Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:34.200

Modified: 2026-09-28T18:36:00.710

Link: CVE-2026-93840

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T19:06:06Z

Links: CVE-2026-93840 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T01:45:19Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index

  • CWE-787

    Out-of-bounds Write