SOURCE-LINKED INTELLIGENCE
GHSA-vc6m-hm49-g9qg: vLLM: Quadratic Time Complexity in Input Token Processing leads to denial of service
### Summary A critical performance vulnerability has been identified in the input preprocessing logic of the multimodal tokenizer. The code dynamically replaces placeholder tokens (e.g., , ) with repeated tokens based on precomputed lengths. Due to inefficient list concatenation operations, the algorithm exhibits quadratic time complexity (O(n²)), allowing malicious actors to trigger resource exhaustion via specially crafted inputs. ### Details Affected Component: input_processor_for_phi4mm function. https://github.com/vllm-project/vllm/blob/8cac35ba435906fb7eb07e44fe1a8c26e8744f4e
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2025-04-29T16:43:10.000Z
- OSV AI package advisories · 2026-07-07T16:02:51.719Z
First collected: 2026-09-20T22:31:48.298Z. This is not the publication date.