CVE-2026-54233Disclosure(vllm / vllm)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcriptions endpoint limits compressed upload size but not decoded PCM output. A 25MB OPUS file expands to ~14.9GB of float32 PCM at decode time. This vulnerability is fixed in 0.23.1rc0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-409

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vllm

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
vllm

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-22: 206-22
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-54233 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcriptions endpoint limits compressed upload size b… https://www.cve.org/CVERecord?id=CVE-2026-54233 ----- Traducción: CVE-2026-54233 vLL… http://infoflow.cloud`

    Post summary

    The tweet merely references CVE-2026-54233 and links to its CVE record, lacking any PoC, exploit, patch, or evidence of active exploitation.

    0000038
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-54233 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcriptions endpoint limits compressed upload size b… https://www.cve.org/CVERecord?id=CVE-2026-54233

    Post summary

    The post references CVE‑2026‑54233, noting a versioned limit issue on vLLM’s /v1/audio/transcriptions endpoint, but provides no PoC, exploit, patch, or detailed technical data – essentially a basic vulnerability disclosure.

    00000668
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvllmvllm---

Explore more