CVE-2026-71486: vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

Published Aug 17, 2026
·
Updated

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied GenerateResponse objects whose generateresponses, choices, tokenids, promptlogprobs, logprobs.content, toplogprobs, and routedexperts structures are processed by OnlineDerenderer and tokenizer.decode before maxmodellen, maxtokens, maxnumseqs, or response-size limits are enforced, allowing an authenticated API client to consume excessive CPU and memory and produce oversized responses. This issue is fixed in version 0.26.0.

Affected Software

1 affected component
vllm<0.26.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade vLLM derender endpoints (/v1/completions/derender and /v1/chat/completions/derender) to a version that resolves this vulnerability.

    Fixed in 0.26.0

Event History

Aug 17, 2026
CVE Published
via MITRE·08:13 PM
Data Sourced
via MITRE·08:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-71486?

The severity of CVE-2026-71486 is medium with a score of 4.3.

2

What does CVE-2026-71486 affect?

CVE-2026-71486 affects vLLM's /v1/completions/derender and /v1/chat/completions/derender endpoints.

3

How do I fix CVE-2026-71486?

To fix CVE-2026-71486, update vLLM to version 0.26.0 or higher.

4

What kind of attack can CVE-2026-71486 lead to?

CVE-2026-71486 can lead to unbounded processing of caller-supplied token IDs, which may result in denial of service.

5

Is CVE-2026-71486 related to data exposure?

CVE-2026-71486 does not involve exposure of confidential information as it primarily affects system availability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203