Vulnerability Details CVE-2026-100648
vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing unauthenticated clients to bypass file size restrictions. Attackers can submit oversized audio files through chat endpoints to consume excessive memory and CPU resources during decoding.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 24.2%
CVSS Severity
CVSS v3 Score 5.3