Vulnerabilities
Vulnerable Software
Security Vulnerabilities
vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). Attackers can supply token IDs above the output vocabulary that pass validation, causing LogitBiasState to corrupt GPU logits state and allow concurrent requests to sample tokens outside their allowlists.
CVSS Score
6.3
EPSS Score
0.002
Published
2026-09-18
vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size. Attackers can submit multimodal audio requests with tokens equal to vocabulary size, causing out-of-bounds writes that corrupt concurrent requests' sampler state and alter repetition penalty behavior.
CVSS Score
6.3
EPSS Score
0.002
Published
2026-09-18
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.
CVSS Score
8.1
EPSS Score
0.004
Published
2026-09-18
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.
CVSS Score
8.8
EPSS Score
0.002
Published
2026-09-18
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
CVSS Score
8.1
EPSS Score
0.005
Published
2026-09-18
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
CVSS Score
7.2
EPSS Score
0.009
Published
2026-09-18
IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-09-18
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
CVSS Score
7.7
EPSS Score
0.005
Published
2026-09-18
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
CVSS Score
8.9
EPSS Score
0.005
Published
2026-09-18
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.
CVSS Score
8.1
EPSS Score
0.006
Published
2026-09-18


Contact Us

Shodan ® - All rights reserved