CVE-2026-103241

Source
https://cve.org/CVERecord?id=CVE-2026-103241
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103241.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-103241
Published
2026-09-30T16:45:13Z
Modified
2026-10-02T03:47:25Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
vllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of service
Details

A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 0.29.1rc0 is able to resolve this issue. This patch is called 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-404"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103241.json"
}
References

Affected packages

Git / github.com/vllm-project/vllm

Affected ranges

Type
GIT
Repo
https://github.com/vllm-project/vllm
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0.1"
        },
        {
            "last_affected":  "0.1"
        },
        {
            "introduced":  "0.2"
        },
        {
            "last_affected":  "0.2"
        },
        {
            "introduced":  "0.3"
        },
        {
            "last_affected":  "0.3"
        },
        {
            "introduced":  "0.4"
        },
        {
            "last_affected":  "0.4"
        },
        {
            "introduced":  "0.5"
        },
        {
            "last_affected":  "0.5"
        },
        {
            "introduced":  "0.6"
        },
        {
            "last_affected":  "0.6"
        },
        {
            "introduced":  "0.7"
        },
        {
            "last_affected":  "0.7"
        },
        {
            "introduced":  "0.8"
        },
        {
            "last_affected":  "0.8"
        },
        {
            "introduced":  "0.9"
        },
        {
            "last_affected":  "0.9"
        },
        {
            "introduced":  "0.10"
        },
        {
            "last_affected":  "0.10"
        },
        {
            "introduced":  "0.11"
        },
        {
            "last_affected":  "0.11"
        },
        {
            "introduced":  "0.12"
        },
        {
            "last_affected":  "0.12"
        },
        {
            "introduced":  "0.13"
        },
        {
            "last_affected":  "0.13"
        },
        {
            "introduced":  "0.14"
        },
        {
            "last_affected":  "0.14"
        },
        {
            "introduced":  "0.15"
        },
        {
            "last_affected":  "0.15"
        },
        {
            "introduced":  "0.16"
        },
        {
            "last_affected":  "0.16"
        },
        {
            "introduced":  "0.17"
        },
        {
            "last_affected":  "0.17"
        },
        {
            "introduced":  "0.18"
        },
        {
            "last_affected":  "0.18"
        },
        {
            "introduced":  "0.19"
        },
        {
            "last_affected":  "0.19"
        },
        {
            "introduced":  "0.20"
        },
        {
            "last_affected":  "0.20"
        },
        {
            "introduced":  "0.21"
        },
        {
            "last_affected":  "0.21"
        },
        {
            "introduced":  "0.22"
        },
        {
            "last_affected":  "0.22"
        },
        {
            "introduced":  "0.23"
        },
        {
            "last_affected":  "0.23"
        },
        {
            "introduced":  "0.24"
        },
        {
            "last_affected":  "0.24"
        },
        {
            "introduced":  "0.25"
        },
        {
            "last_affected":  "0.25"
        },
        {
            "introduced":  "0.26.0"
        },
        {
            "last_affected":  "0.26.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.1
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
0.21
0.22
0.23
0.24
0.25
0.26.0
0.3
0.4
0.5
0.6
0.7
0.8
0.9
proto-v0.*
proto-v0.1.0
v0.*
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.10.0
v0.10.0rc1
v0.10.0rc2
v0.10.1rc1
v0.10.2rc1
v0.10.2rc2
v0.11.0rc1
v0.11.1
v0.11.1rc0
v0.11.1rc1
v0.11.1rc2
v0.11.1rc3
v0.11.1rc4
v0.11.1rc5
v0.11.1rc6
v0.13.0rc1
v0.14.0rc0
v0.14.0rc1
v0.15.0rc1
v0.15.2rc0
v0.16.0rc0
v0.16.0rc1
v0.17.0rc0
v0.17.1rc0
v0.17.2rc0
v0.18.0rc0
v0.18.1rc0
v0.18.2rc0
v0.19.1rc0
v0.19.2rc0
v0.2.0
v0.2.1
v0.2.2
v0.2.3
v0.2.4
v0.2.5
v0.2.6
v0.2.7
v0.20.1rc0
v0.20.2rc0
v0.21.1rc0
v0.22.1rc0
v0.23.1rc0
v0.25.0
v0.26.1rc0
v0.27.2rc0
v0.28.1rc0
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.4.0
v0.4.0.post1
v0.4.1
v0.4.2
v0.4.3
v0.5.0
v0.5.0.post1
v0.5.1
v0.5.2
v0.5.3
v0.5.3.post1
v0.5.4
v0.5.5
v0.6.0
v0.6.1
v0.6.1.post1
v0.6.1.post2
v0.6.2
v0.6.3
v0.6.3.post1
v0.6.4
v0.6.4.post1
v0.6.5
v0.6.6
v0.6.6.post1
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.8.0rc1
v0.8.0rc2
v0.8.1
v0.8.2
v0.8.3rc1
v0.8.4
v0.9.0
v0.9.1
v0.9.1rc1
v0.9.1rc2
v0.9.2rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103241.json"