{"id":"CVE-2026-69147","aliases":["GHSA-8pw2-6jv3-mj5j"],"url":"https://o3.security/vulnerability/CVE-2026-69147","summary":"vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation","details":"vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, and MediaConnector.fetch_video forwards that choice to VideoMediaIO even when startup configuration selected a software decoder. The engine's _reserve_mm_ipc_gpu_memory logic budgets decoder memory only from static configuration, so the request-selected VIDEO_LOADER_REGISTRY backend can create a CUDA context, decoder surfaces, and decoded-frame allocations that were not removed from the engine's KV-cache budget. An attacker able to submit video requests to a video-capable GPU deployment with PyNvVideoCodec installed can exhaust shared GPU memory, causing request failures, worker crashes, or denial of service. The first release containing the fix is version 0.28.0.","published":"2026-09-16T17:49:20.427Z","modified":"2026-09-18T03:48:28.456873255Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"vllm","fixedVersion":"0.28.0"}],"fix":{"url":"https://github.com/vllm-project/vllm/commit/283893c72292ede38d277e3cd2b9b64c3e4f1dda","label":"vllm-project/vllm@283893c"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69147.json"},{"type":"ADVISORY","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-8pw2-6jv3-mj5j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69147"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/283893c72292ede38d277e3cd2b9b64c3e4f1dda"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/commit/ba22152096b2484faa3579624a253d54804d876d"},{"type":"FIX","url":"https://github.com/vllm-project/vllm/pull/47259"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-18T03:48:28.456873255Z"}}