A security advisory published on GitHub disclosed CVE-2026-105760, a medium-severity vulnerability in vLLM versions 0.23.0rc2 through 0.29.x that allows remote callers to trigger CPU and memory exhaustion via the GLMGA video sampler1. The advisory said attackers can supply large fps and max_frames values through the OpenAI-compatible chat endpoint's media_io_kwargs parameter, causing disproportionate intermediate list construction even with a two-frame video file. The flaw is patched in vLLM 0.30.0. No memory corruption, data disclosure, or code execution was claimed.
vLLM Patches Denial-of-Service Flaw in GLMGA Video Sampling
CVE-2026-105760 allows remote CPU and memory exhaustion in vLLM via GLMGA video sampling; patched in version 0.30.0, per a GitHub security advisory.