Feed/CVE-2026-55514
CVE-2026-55514HIGHCVSS 0.0

CVE-2026-55514

Published Jul 6, 2026·Updated Jul 20, 2026

NVD Description

vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with a model using M-RoPE causes EngineCore to fail an assertion and fatally crash, shutting down the entire server application. Any remote user who is authorized to make a /v1/completions request can make such a request and induce a crash. This issue is fixed in version 0.24.0.

Affected Packages (1)

vllmPYPI
From 0.12.0
Fixed in 0.24.0

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free