CVE-2026-54234: vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative decoding workload can cause the rejection sampler t...

Added to the CISA Known Exploited Vulnerabilities catalog on 06 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.5.

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative decoding workload can cause the rejection sampler to produce a recovered token equal to the model vocabulary size boundary value, which is then convert...

Required action: Review and patch if applicable to your AI infrastructure.