vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with a model using M-RoPE causes EngineCore to fail an assertion and fatally crash, shutting down the entire server application. Any remote user who is authorized to make a /v1/completions request can make such a request and induce a crash. This issue is fixed in version 0.24.0.
References
| Link | Resource |
|---|---|
| https://github.com/vllm-project/vllm/commit/470229c37efaf69c86e8bc97482b0b1ff7551c65 | Patch |
| https://github.com/vllm-project/vllm/pull/45252 | Issue Tracking Patch |
| https://github.com/vllm-project/vllm/releases/tag/v0.24.0 | Release Notes |
| https://github.com/vllm-project/vllm/security/advisories/GHSA-33cg-gxv8-3p8g | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-07-06 21:16
Updated : 2026-07-07 19:02
NVD link : CVE-2026-55514
Mitre link : CVE-2026-55514
CVE.ORG link : CVE-2026-55514
JSON object : View
Products Affected
vllm
- vllm
CWE
CWE-617
Reachable Assertion
