{"api_version":"1","generated_at":"2026-10-01T05:18:57+00:00","cve":"CVE-2026-103241","urls":{"html":"https://cve.report/CVE-2026-103241","api":"https://cve.report/api/cve/CVE-2026-103241.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-103241","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-103241"},"summary":{"title":"vllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of service","description":"A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 0.29.1rc0 is able to resolve this issue. This patch is called 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised.","state":"PUBLISHED","assigner":"VulDB","published_at":"2026-09-30 17:16:42","updated_at":"2026-09-30 17:31:44"},"problem_types":["CWE-404","CWE-404 Denial of Service"],"metrics":[{"version":"4.0","source":"cna@vuldb.com","type":"Secondary","score":"5.5","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"DECLARED","score":"6.9","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","data":{"baseScore":6.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","version":"4.0"}},{"version":"3.1","source":"cna@vuldb.com","type":"Primary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C","data":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C","version":"3.1"}},{"version":"3.0","source":"CNA","type":"DECLARED","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C","data":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C","version":"3.0"}},{"version":"2.0","source":"cna@vuldb.com","type":"Secondary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}},{"version":"2.0","source":"CNA","type":"DECLARED","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C","data":{"baseScore":5,"vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C","version":"2.0"}}],"references":[{"url":"https://vuldb.com/vuln/411965","name":"https://vuldb.com/vuln/411965","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/submit/956250","name":"https://vuldb.com/submit/956250","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/vllm-project/vllm/pull/54303","name":"https://github.com/vllm-project/vllm/pull/54303","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/vllm-project/vllm/issues/50927","name":"https://github.com/vllm-project/vllm/issues/50927","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/vllm-project/vllm/commit/3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9","name":"https://github.com/vllm-project/vllm/commit/3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/vllm-project/vllm/releases/tag/v0.29.1rc0","name":"https://github.com/vllm-project/vllm/releases/tag/v0.29.1rc0","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://gist.github.com/Yunzez/8e98d656aa667095b513161eb056d28e","name":"https://gist.github.com/Yunzez/8e98d656aa667095b513161eb056d28e","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/vuln/411965/cti","name":"https://vuldb.com/vuln/411965/cti","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/vllm-project/vllm/","name":"https://github.com/vllm-project/vllm/","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/cve/CVE-2026-103241","name":"https://vuldb.com/cve/CVE-2026-103241","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-103241","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103241","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.1","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.2","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.3","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.4","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.5","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.6","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.7","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.8","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.9","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.10","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.11","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.12","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.13","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.14","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.15","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.16","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.17","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.18","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.19","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.20","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.21","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.22","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.23","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.24","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.25","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"affected 0.26.0","platforms":[]},{"source":"CNA","vendor":"vllm-project","product":"vLLM","version":"unaffected 0.29.1rc0","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-09-30T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"source":"CNA","time":"2026-09-30T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"source":"CNA","time":"2026-09-30T12:42:01.000Z","lang":"en","value":"VulDB entry last update"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Zyz3366 (VulDB User)","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:vllm-project:vllm:*:*:*:*:*:*:*:*"],"modules":["Gemma4UnifiedParser"],"product":"vLLM","vendor":"vllm-project","versions":[{"status":"affected","version":"0.1"},{"status":"affected","version":"0.2"},{"status":"affected","version":"0.3"},{"status":"affected","version":"0.4"},{"status":"affected","version":"0.5"},{"status":"affected","version":"0.6"},{"status":"affected","version":"0.7"},{"status":"affected","version":"0.8"},{"status":"affected","version":"0.9"},{"status":"affected","version":"0.10"},{"status":"affected","version":"0.11"},{"status":"affected","version":"0.12"},{"status":"affected","version":"0.13"},{"status":"affected","version":"0.14"},{"status":"affected","version":"0.15"},{"status":"affected","version":"0.16"},{"status":"affected","version":"0.17"},{"status":"affected","version":"0.18"},{"status":"affected","version":"0.19"},{"status":"affected","version":"0.20"},{"status":"affected","version":"0.21"},{"status":"affected","version":"0.22"},{"status":"affected","version":"0.23"},{"status":"affected","version":"0.24"},{"status":"affected","version":"0.25"},{"status":"affected","version":"0.26.0"},{"status":"unaffected","version":"0.29.1rc0"}]}],"credits":[{"lang":"en","type":"reporter","value":"Zyz3366 (VulDB User)"}],"descriptions":[{"lang":"en","value":"A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 0.29.1rc0 is able to resolve this issue. This patch is called 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised."}],"metrics":[{"cvssV4_0":{"baseScore":6.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","version":"4.0"}},{"cvssV3_1":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C","version":"3.1"}},{"cvssV3_0":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C","version":"3.0"}},{"cvssV2_0":{"baseScore":5,"vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C","version":"2.0"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-404","description":"Denial of Service","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-30T16:45:13.581Z","orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB"},"references":[{"name":"VDB-411965 | vllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of service","tags":["vdb-entry"],"url":"https://vuldb.com/vuln/411965"},{"name":"VDB-411965 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"],"url":"https://vuldb.com/vuln/411965/cti"},{"name":"CVE-2026-103241 | CVE Analysis and Report","tags":["third-party-advisory"],"url":"https://vuldb.com/cve/CVE-2026-103241"},{"name":"Submit #956250 | vLLM Project vLLM v0.26.0 Denial of Service","tags":["third-party-advisory"],"url":"https://vuldb.com/submit/956250"},{"tags":["issue-tracking"],"url":"https://github.com/vllm-project/vllm/issues/50927"},{"tags":["issue-tracking","patch"],"url":"https://github.com/vllm-project/vllm/pull/54303"},{"tags":["exploit"],"url":"https://gist.github.com/Yunzez/8e98d656aa667095b513161eb056d28e"},{"tags":["patch"],"url":"https://github.com/vllm-project/vllm/commit/3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9"},{"tags":["patch"],"url":"https://github.com/vllm-project/vllm/releases/tag/v0.29.1rc0"},{"tags":["product"],"url":"https://github.com/vllm-project/vllm/"}],"tags":["x_open-source"],"timeline":[{"lang":"en","time":"2026-09-30T00:00:00.000Z","value":"Advisory disclosed"},{"lang":"en","time":"2026-09-30T02:00:00.000Z","value":"VulDB entry created"},{"lang":"en","time":"2026-09-30T12:42:01.000Z","value":"VulDB entry last update"}],"title":"vllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of service","x_generator":["VulDB PVTS v202609"]}},"cveMetadata":{"assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","assignerShortName":"VulDB","cveId":"CVE-2026-103241","datePublished":"2026-09-30T16:45:13.581Z","dateReserved":"2026-09-30T10:36:13.164Z","dateUpdated":"2026-09-30T16:45:13.581Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-30 17:16:42","lastModifiedDate":"2026-09-30 17:31:44","problem_types":["CWE-404","CWE-404 Denial of Service"],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"103241","Ordinal":"1","Title":"vllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of servic","CVE":"CVE-2026-103241","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"103241","Ordinal":"1","NoteData":"A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 0.29.1rc0 is able to resolve this issue. This patch is called 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised.","Type":"Description","Title":"vllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of servic"}]}}}