CVE-2026-90555: Improper Handling of Highly Compressed Data (Data Amplification) in vllm-project vLLM
CVE-2026-90555 is a vulnerability in vLLM versions before 0.28.0 where the transcription endpoint improperly handles audio sample rate headers. Authenticated clients can submit forged FLAC headers with inflated sample rates, bypassing duration checks and causing excessive memory allocation that crashes the API server process, impacting all tenants.
AI Analysis
Technical Summary
vLLM versions prior to 0.28.0 do not validate audio sample rate headers in the transcription endpoint, allowing authenticated users to bypass duration checks. By submitting forged FLAC headers with artificially inflated sample rates, attackers can cause the server to allocate excessive memory, leading to a crash of the API server process and denial of service affecting all tenants.
Potential Impact
Successful exploitation results in denial of service by crashing the API server process through excessive memory allocation. This affects all tenants relying on the transcription endpoint, potentially disrupting service availability.
Mitigation Recommendations
A fix is available in vLLM version 0.28.0 and later. Users should upgrade to version 0.28.0 or newer to remediate this vulnerability.
CVE-2026-90555: Improper Handling of Highly Compressed Data (Data Amplification) in vllm-project vLLM
Description
CVE-2026-90555 is a vulnerability in vLLM versions before 0.28.0 where the transcription endpoint improperly handles audio sample rate headers. Authenticated clients can submit forged FLAC headers with inflated sample rates, bypassing duration checks and causing excessive memory allocation that crashes the API server process, impacting all tenants.
CVSS v4.0
Score 7.1high
Affected software
vllm-project
vLLM
pkg:github/vllm-project/vllmRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
vLLM versions prior to 0.28.0 do not validate audio sample rate headers in the transcription endpoint, allowing authenticated users to bypass duration checks. By submitting forged FLAC headers with artificially inflated sample rates, attackers can cause the server to allocate excessive memory, leading to a crash of the API server process and denial of service affecting all tenants.
Potential Impact
Successful exploitation results in denial of service by crashing the API server process through excessive memory allocation. This affects all tenants relying on the transcription endpoint, potentially disrupting service availability.
Mitigation Recommendations
A fix is available in vLLM version 0.28.0 and later. Users should upgrade to version 0.28.0 or newer to remediate this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-12T11:13:43.326Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa5465455bf5e2cf54629eb
Added to database: 09/12/2026, 12:32:20 UTC
Last enriched: 09/12/2026, 12:46:26 UTC
Last updated: 09/12/2026, 13:14:39 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.