YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0091

Incident record

One negative token ID crashes the GPU behind vLLM's embeddings routes until a restart

Severity
High
Status
Patched
Type
Infra Vuln
Target
vLLM before 0.28.0, /v1/embeddings and /pooling endpoints
Actor
researcher
CVE
CVE-2026-93592

What happened

vLLM validated only the upper bound of token IDs on the embeddings and pooling routes, so one unauthenticated request carrying a negative token ID triggers a CUDA device-side assertion that takes down the GPU context until the server restarts. Scored CVSS 3.1 7.5 and fixed in 0.28.0.

The advisory published 3 September; the CVE record reached NVD on 18 September through VulnCheck, a paperwork catch-up on an already-patched flaw.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026