YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0089

Incident record

Four vLLM advisories in one day, each an unauthenticated request that stalls or bloats the server

Severity
Medium
Status
Patched
Type
Infra Vuln
Target
vLLM before 0.29.0
Actor
researcher

What happened

Four denial-of-service advisories published together and fixed in 0.29.0: an unbounded cache_salt parameter that stalls the single scheduler thread, audio decoding that ignores the configured clip-size limit, sampler-subclass attribute shadowing that bypasses decoder-slot and GPU-memory limits, and remote media fetched in full across four ingress paths before size limits apply. CVSS scores run 3.7 to 6.5 and none carries a CVE yet.

All four are reachable without credentials on exposed endpoints. The remote-media advisory is the widest: any of four ingress paths materialises the whole fetch before checking size.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026