CVE-2026-54235
Last modified
CVE-2026-54235 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation gates use comparison operators (<, >), which silently evaluate to False for NaN and for positive Infinity in Python's IEEE 754 float semantics. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation gates use comparison operators (<, >), which silently evaluate to False for NaN and for positive Infinity in Python's IEEE 754 float semantics. Both values pass every guard and propagate to GPU sampling kernels, where they produce undefined behavior or CUDA errors that can crash the inference worker. This vulnerability is fixed in 0.23.1rc0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vllm | Vllm | < 0.23.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-54235?
How severe is CVE-2026-54235?
How do I fix CVE-2026-54235?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5423@neo4j/graphql library versions prior to 7.5.6 fail to verif…8.2
- CVE-2026-54230A symlink following vulnerability was found in the ABRT post…7.8
- CVE-2026-54231A content injection vulnerability was found in the ABRT post…5.5
- CVE-2026-54232vLLM is an inference and serving engine for large language m…8.8
- CVE-2026-54233vLLM is an inference and serving engine for large language m…6.5
- CVE-2026-54234vLLM is a high-throughput and memory-efficient inference and…7.5
- CVE-2026-54236vLLM is an inference and serving engine for large language m…5.3
- CVE-2026-54237Wavelog is web-based amateur radio logging software. From 1.…9.3
- CVE-2026-54239Faust.js is a headless WordPress toolkit. Prior to 1.8.11, t…8.8
- CVE-2026-54240libde265 is an open source implementation of the h.265 video…7.4
- CVE-2026-54241libde265 is an open source implementation of the h.265 video…7.4
- CVE-2026-54242Statamic is a Laravel and Git powered content management sys…4.9
Are you affected by CVE-2026-54235?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
