CVE-2026-103241: vllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of service
A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 0.29.1rc0 is able to resolve this issue. This patch is called 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vllm-project vLLMto a version that resolves this vulnerability.Fixed in 0.29.1rc0Patch 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be launched remotely and requires no privileges or user interaction, according to the supplied vector. An exploit has been published, increasing the likelihood of attempted exploitation.
Which deployments are affected?
vLLM versions up to 0.26.0 are identified as affected. The issue is in the Gemma4UnifiedParser component, in rust/src/parser/src/unified/gemma4.rs.
What is the impact of successful exploitation?
Successful manipulation can cause a denial of service. The provided vector indicates availability impact only, with no stated confidentiality or integrity impact.
What remediation is available?
Upgrade to vLLM version 0.29.1rc0 or later as indicated by the advisory. The resolving patch is 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9.