AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

GHSA-8wr5-jm2h-8r4f: vLLM has Remote DoS via Invalid Recovered Token Reinjection

OSV AI package advisories · observation · Jul 17, 2026 · UTC

## Summary A frontend-legal multi-request speculative workload can make vLLM produce an out-of-vocabulary recovered token equal to `vocab_size`, convert that value to `-1` when choosing the next live token for a request, and then feed that `-1` back into the next drafter input ids. On Qwen3 GPTQ this reaches the worker-side drafting / attention path and crashes the engine with a GPU `device-side assert`. The same issue is reachable through the public gRPC request surface by sending a specific overlapping `Generate` / `Abort` sequence. ## Impact - A remote client that can send public gRPC gener

Read original source ↗ Open in workspace

recordType
vulnerability
status
active
evidenceStatus
reported
region
Global

Evidence & attribution

First collected: 2026-09-20T22:31:48.298Z. This is not the publication date.