Saturday, 19 September 2026
0 agent hacks today 8 vs yesterday (8)

vLLM unauthenticated audio decompression-bomb DoS in /v1/chat/completions

vLLM's audio decode-duration guard is only applied to the speech-to-text endpoint but not the chat endpoint, allowing unauthenticated clients to submit compressed audio files that expand to multiple GB and cause out-of-memory denial of service attacks.

Disclosed 16 September 2026 · Record updated 17 September 2026

Impact

Unauthenticated remote denial of service via memory amplification on audio-capable model deployments with default no-auth configuration.

Our coverage

Sources

  1. github.comhttps://github.com/advisories/GHSA-hcwq-8wjf-3gcr