Skip to content
VECTOR WIREAI INTELLIGENCE
UTC

vLLM Discloses Unauthenticated DoS Flaw in Qwen Video Backends, GitHub Advisory Says

GitHub advisory CVE-2026-105758 details a medium-severity memory-exhaustion vulnerability in vLLM affecting Qwen2-VL and Qwen3-VL deployments, patched in…

A medium-severity vulnerability (CVE-2026-105758) in vLLM allows unauthenticated remote attackers to exhaust API-server memory on deployments serving Qwen2-VL or Qwen3-VL models by manipulating request-level max_frames and fps parameters, according to a GitHub security advisory1. Versions 0.24.0 through 0.29.x are affected; version 0.30.0 is patched. The advisory states that a prior fix capping num_frames (PR #51969) does not reach the Qwen samplers, which ignore that parameter entirely. The /tokenize and /invocations endpoints remain unauthenticated even when an API key is configured, the advisory said.