CVE-2026-105775: vllm-project vLLM Completions Request mamba_mixer2.py conv_ssm_forward out-of-bounds
A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function convssmforward of the file vllm/modelexecutor/layers/mamba/mambamixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be performed remotely and requires low privileges. No user interaction is required.
How should teams prioritize this issue?
A public exploit has been disclosed, and affected versions include vLLM up to 0.31.0. The project had not responded to the reported issue at the time of the available information.