{"id":"GHSA-78fp-cf4h-g36p","summary":"Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164","details":"### Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-mcmc-2m55-j8jj. This link is maintained to preserve external references.\n\n### Original Description\n\nvLLM versions \u003e= 0.10.2 and \u003c 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests with malformed (negative or out-of-bounds) tensor indices, when the prompt-embeds feature is enabled, to trigger crashes or resource exhaustion (denial of service), with potential for out-of-bounds/write-what-where memory corruption. This continues CVE-2025-62164, whose prior fix only disabled the feature by default rather than addressing the root cause.","modified":"2026-09-11T19:30:05.032946085Z","published":"2026-06-20T21:31:21Z","withdrawn":"2026-09-11T19:18:42Z","database_specific":{"github_reviewed_at":"2026-09-11T19:18:42Z","nvd_published_at":"2026-06-20T19:16:23Z","cwe_ids":["CWE-20","CWE-787"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-mcmc-2m55-j8jj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56340"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-56340"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491060"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56340.json"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/vllm-denial-of-service-via-unvalidated-multimodal-embeddings"}],"affected":[{"package":{"name":"vllm","ecosystem":"PyPI","purl":"pkg:pypi/vllm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.10.2"},{"fixed":"0.13.0"}]}],"versions":["0.10.2","0.11.0","0.11.1","0.11.2","0.12.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-78fp-cf4h-g36p/GHSA-78fp-cf4h-g36p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}