Vulnerability  ·  2026-10-01

vLLM Gemma4UnifiedParser denial of service (remote)

VulnerabilityMedium impactGlobalCVE-2026-103241
NVD rated this a remote DoS in one of the most widely deployed open-source serving stacks, with a public PoC gist. It is part of an ongoing stream of parser/handling DoS findings in vLLM's unified tokenizer/serving path.
vLLM is core production inference infrastructure; an unauthenticated remote DoS in the request-parsing path lets anyone with API access take down model-serving capacity without authentication or privileges, directly affecting availability of AI deployments.
A remote attacker sends crafted Gemma-4 unified-format input that triggers unbounded/failing processing in the Gemma4UnifiedParser Rust parser, causing denial of service in the inference server.
vLLM up to 0.26.0 (rust/src/parser/src/unified/gemma4.rs, Gemma4UnifiedParser)
Upgrade vLLM beyond 0.26.0; rate-limit/validate model-input parsing until patched.
NVDPublic PoC gistVulDB record
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →