Official source evidenceGitHubGHSA-25Q3-V2HM-8VPF
Official source article · GitHub

GHSA-25Q3-V2HM-8VPF: Denial of service: a negative token id in `/v1/embeddings` or `/pooling` input kills the vLLM engine via a CUDA device-side assertion · Advisory · vllm-project/vllm · GitHub

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
PublisherGitHub
Article IDGHSA-25Q3-V2HM-8VPF
Verified snapshot28 Sept 2026, 20:28 UTC
Linked CVEs1

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-93592vLLM before 0.28.0 Denial of Service via negative token ID

Source and provenance

Original title: Denial of service: a negative token id in `/v1/embeddings` or `/pooling` input kills the vLLM engine via a CUDA device-side assertion · Advisory · vllm-project/vllm · GitHub. Captured 28 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗