CVE-2026-54235Disclosure(vllm / vllm)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch vllm vllm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation gates use comparison operators (<, >), which silently evaluate to False for NaN and for positive Infinity in Python's IEEE 754 float semantics. Both values pass every guard and propagate to GPU sampling kernels, where they produce undefined behavior or CUDA errors that can crash the inference worker. This vulnerability is fixed in 0.23.1rc0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vllm

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
vllm

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-22: 2Patch / Workaround · 2026-06-22: 1Technical Details · 2026-06-22: 206-22
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-54235 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation gates use comparison operators (&lt;, &gt;), which s… https://www.cve.org/CVERecord?id=CVE-2026-54235 ----- Traducción: CVE-2026-54235 vLL… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-54235 in vLLM, noting that before version 0.23.1rc0 temperature validation improperly used comparison operators, and that upgrading to 0.23.1rc0 addresses the issue.

    0000038
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-54235 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation gates use comparison operators (&lt;, &gt;), which s… https://www.cve.org/CVERecord?id=CVE-2026-54235

    Post summary

    The post announces CVE‑2026‑54235 in vLLM, noting a validation flaw in versions prior to 0.23.1rc0, with no evidence of exploitation or mitigations.

    00000725
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvllmvllm---

Explore more