Vulnerability Details CVE-2026-100649
vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler subclass shadowing allows independent counter increments. Unauthenticated attackers can select different sampler subclasses in video requests to exceed configured decoder limits and exhaust unaccounted GPU memory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 21.7%
CVSS Severity
CVSS v3 Score 3.7