SOURCE-LINKED INTELLIGENCE
GHSA-v82g-2437-67m2: vLLM: Speech-to-text upload size limit is enforced after full UploadFile read
## Summary Current-head vLLM documents `VLLM_MAX_AUDIO_CLIP_FILESIZE_MB` as the maximum audio file size accepted by the speech-to-text APIs. The default is 25 MB. `vllm/envs.py` also describes files larger than this value as rejected. The `/v1/audio/transcriptions` and `/v1/audio/translations` routes call `await request.file.read()` before vLLM checks that limit. In FastAPI and Starlette, `UploadFile.read()` returns bytes from the uploaded file object; when called without a size argument, the route materializes the remaining file contents. vLLM then performs the compressed file-size check late
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2026-07-17T17:16:17.000Z
- OSV AI package advisories · 2026-07-06T20:16:37.663Z
First collected: 2026-09-20T22:31:48.298Z. This is not the publication date.