CVE-2026-90713

Source
https://cve.org/CVERecord?id=CVE-2026-90713
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90713.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90713
Published
2026-09-14T12:00:10Z
Modified
2026-09-17T03:31:10Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
vllm-project vLLM tiktoken vocab File mod.rs new denial of service
Details

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-404"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90713.json"
}
References

Affected packages

Git / github.com/vllm-project/vllm

Affected ranges

Type
GIT
Repo
https://github.com/vllm-project/vllm
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.1"
        },
        {
            "last_affected": "0.1"
        },
        {
            "introduced": "0.2"
        },
        {
            "last_affected": "0.2"
        },
        {
            "introduced": "0.3"
        },
        {
            "last_affected": "0.3"
        },
        {
            "introduced": "0.4"
        },
        {
            "last_affected": "0.4"
        },
        {
            "introduced": "0.5"
        },
        {
            "last_affected": "0.5"
        },
        {
            "introduced": "0.6"
        },
        {
            "last_affected": "0.6"
        },
        {
            "introduced": "0.7"
        },
        {
            "last_affected": "0.7"
        },
        {
            "introduced": "0.8"
        },
        {
            "last_affected": "0.8"
        },
        {
            "introduced": "0.9"
        },
        {
            "last_affected": "0.9"
        },
        {
            "introduced": "0.10"
        },
        {
            "last_affected": "0.10"
        },
        {
            "introduced": "0.11"
        },
        {
            "last_affected": "0.11"
        },
        {
            "introduced": "0.12"
        },
        {
            "last_affected": "0.12"
        },
        {
            "introduced": "0.13"
        },
        {
            "last_affected": "0.13"
        },
        {
            "introduced": "0.14"
        },
        {
            "last_affected": "0.14"
        },
        {
            "introduced": "0.15"
        },
        {
            "last_affected": "0.15"
        },
        {
            "introduced": "0.16"
        },
        {
            "last_affected": "0.16"
        },
        {
            "introduced": "0.17"
        },
        {
            "last_affected": "0.17"
        },
        {
            "introduced": "0.18"
        },
        {
            "last_affected": "0.18"
        },
        {
            "introduced": "0.19"
        },
        {
            "last_affected": "0.19"
        },
        {
            "introduced": "0.20"
        },
        {
            "last_affected": "0.20"
        },
        {
            "introduced": "0.21"
        },
        {
            "last_affected": "0.21"
        },
        {
            "introduced": "0.22"
        },
        {
            "last_affected": "0.22"
        },
        {
            "introduced": "0.23"
        },
        {
            "last_affected": "0.23"
        },
        {
            "introduced": "0.24"
        },
        {
            "last_affected": "0.24"
        },
        {
            "introduced": "0.25"
        },
        {
            "last_affected": "0.25"
        },
        {
            "introduced": "0.26"
        },
        {
            "last_affected": "0.26"
        },
        {
            "introduced": "0.27"
        },
        {
            "last_affected": "0.27"
        },
        {
            "introduced": "0.28"
        },
        {
            "last_affected": "0.28"
        },
        {
            "introduced": "0.29.0"
        },
        {
            "last_affected": "0.29.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.1
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
0.21
0.22
0.23
0.24
0.25
0.26
0.27
0.28
0.29.0
0.3
0.4
0.5
0.6
0.7
0.8
0.9
v0.*
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.10.0
v0.10.0rc1
v0.10.0rc2
v0.10.1rc1
v0.10.2rc1
v0.10.2rc2
v0.11.0rc1
v0.11.1
v0.11.1rc0
v0.11.1rc1
v0.11.1rc2
v0.11.1rc3
v0.11.1rc4
v0.11.1rc5
v0.11.1rc6
v0.13.0rc1
v0.14.0rc0
v0.14.0rc1
v0.15.0rc1
v0.15.2rc0
v0.16.0rc0
v0.16.0rc1
v0.17.0rc0
v0.17.1rc0
v0.17.2rc0
v0.18.0rc0
v0.18.1rc0
v0.18.2rc0
v0.19.1rc0
v0.19.2rc0
v0.2.0
v0.2.1
v0.2.2
v0.2.3
v0.2.4
v0.2.5
v0.2.6
v0.2.7
v0.20.1rc0
v0.20.2rc0
v0.21.1rc0
v0.22.1rc0
v0.23.1rc0
v0.25.0
v0.26.1rc0
v0.27.2rc0
v0.28.1rc0
v0.29.0
v0.29.0rc1
v0.29.0rc2
v0.29.0rc3
v0.29.0rc4
v0.29.0rc5
v0.29.0rc6
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.4.0
v0.4.0.post1
v0.4.1
v0.4.2
v0.4.3
v0.5.0
v0.5.0.post1
v0.5.1
v0.5.2
v0.5.3
v0.5.3.post1
v0.5.4
v0.5.5
v0.6.0
v0.6.1
v0.6.1.post1
v0.6.1.post2
v0.6.2
v0.6.3
v0.6.3.post1
v0.6.4
v0.6.4.post1
v0.6.5
v0.6.6
v0.6.6.post1
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.8.0rc1
v0.8.0rc2
v0.8.1
v0.8.2
v0.8.3rc1
v0.8.4
v0.9.0
v0.9.1
v0.9.1rc1
v0.9.1rc2
v0.9.2rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90713.json"