Vulnerability  ·  2026-09-16

vLLM tiktoken vocab file handler — local denial of service via TiktokenTokenizer::new

VulnerabilityLow impactGlobalCVE-2026-90713
A denial-of-service flaw exists in vLLM's Rust-based tiktoken tokenizer vocab-file handling, crashing the affected component when triggered locally.
Low urgency given the local-attacker precondition, but worth tracking for any vLLM deployment that allows less-trusted local users (e.g., shared multi-user inference hosts) to interact with the tokenizer loading path.
A local attacker can trigger a flaw in the TiktokenTokenizer::new function of the tiktoken vocab file handler (rust/src/text/src/backend/hf/mod.rs), causing a crash and denial of service; exploitation requires local access, limiting the practical blast radius.
vllm-project vLLM, versions up to 0.29.0 (Rust tiktoken backend)
Track the upstream vLLM fix and upgrade when available; this is a local-only, low-severity issue and does not require emergency action for typical remote-facing deployments.
NVDRed Hat CVE Database
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →