Disclosure summary
A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 0.29.1rc0 is able to resolve this issue. This patch is called 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised.
Source-reported weakness categories
CWE-404
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-103241
Open original source · Updated Oct 02, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
- NIST NVD record
- CVE Program record
- gist.github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- vuldb.com
- vuldb.com
- vuldb.com
- vuldb.com
PUBLISHED 2026-09-30T13:16:42-04:00
MODIFIED 2026-10-02T13:17:02-04:00
INGESTED 2026-10-06T11:44:59-04:00