CVE-2026-100649
Description
A flaw was found in vLLM. An unauthenticated remote attacker can cause a Denial of Service (DoS) by submitting video processing requests that specify different sampler subclasses. Because active decoder counters are tracked independently across subclasses rather than globally, requests can bypass configured hardware decoder limits. This issue allows an attacker to exhaust Graphics Processing Unit (GPU) memory, resulting in allocation failures and service disruption.
Statement
Red Hat is not impacted as our portfolio makes use of vllm versions ranging from 0.8.5-0.24.0. And none of these versions include the PyNvVideoCodec decoder-slot / sampler-subclass path. All of these only have opencv-style loaders and no pynvvideocodec.
Mitigation
1. Summary of action: Restrict network reachability to the inference server and avoid deploying models with the hardware-accelerated PyNvVideoCodec video backend.
2. Command examples:
To block direct untrusted network access to the vLLM server port (default 8000) using firewalld:
firewall-cmd --permanent --zone=public --remove-port=8000/tcpIn OpenShift environments, deploy a NetworkPolicy to restrict ingress traffic so that only authenticated API gateways or designated client pods can reach the inference service. Additionally, avoid specifying "backend": "pynvvideocodec" in the server video configuration.
firewall-cmd --permanent --zone=trusted --add-source=<TRUSTED_IP_OR_CIDR>
firewall-cmd --reload
3. Caveats: Restricting network access prevents direct unauthenticated requests from reaching the endpoint. Avoiding hardware-accelerated video decoding shifts media decoding workloads to software, which may increase CPU utilization and inference latency for video inputs.
4. Warning: Applying firewall rule reloads takes effect immediately and may sever existing connections. Modifying deployment configurations or restarting inference pods will temporarily interrupt ongoing serving sessions.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 3.7 | N/A | 3.7 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | High | N/A | High |
| Privileges Required | None | N/A | None |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | None | N/A | None |
| Integrity Impact | None | N/A | None |
| Availability Impact | Low | N/A | Low |
Vector
Red Hat: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
cve.org: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)
When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.