What happened
NVD rated this a remote DoS in one of the most widely deployed open-source serving stacks, with a public PoC gist. It is part of an ongoing stream of parser/handling DoS findings in vLLM's unified tokenizer/serving path.
Why it matters
vLLM is core production inference infrastructure; an unauthenticated remote DoS in the request-parsing path lets anyone with API access take down model-serving capacity without authentication or privileges, directly affecting availability of AI deployments.
Attack vector
A remote attacker sends crafted Gemma-4 unified-format input that triggers unbounded/failing processing in the Gemma4UnifiedParser Rust parser, causing denial of service in the inference server.
Affected systems
vLLM up to 0.26.0 (rust/src/parser/src/unified/gemma4.rs, Gemma4UnifiedParser)
Mitigation
Upgrade vLLM beyond 0.26.0; rate-limit/validate model-input parsing until patched.