{"id":"CVE-2026-55514","aliases":["GHSA-33cg-gxv8-3p8g","PYSEC-2026-2303"],"url":"https://o3.security/vulnerability/CVE-2026-55514","summary":"vLLM denial of service via prompt embeds on M-RoPE models","details":"vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with a model using M-RoPE causes EngineCore to fail an assertion and fatally crash, shutting down the entire server application. Any remote user who is authorized to make a /v1/completions request can make such a request and induce a crash. This issue is fixed in version 0.24.0.","published":"2026-07-06T20:07:40.405Z","modified":"2026-08-12T03:51:49.391924653Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"vllm","fixedVersion":"0.24.0"}],"fix":{"url":"https://github.com/vllm-project/vllm/commit/470229c37efaf69c86e8bc97482b0b1ff7551c65","label":"vllm-project/vllm@470229c"},"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/releases/tag/v0.24.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55514.json"},{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-33cg-gxv8-3p8g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55514"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/470229c37efaf69c86e8bc97482b0b1ff7551c65"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/pull/45252"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:49.391924653Z"}}