THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-34755 (MEDIUM 6.5) — vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.load_base64() method at vllm/multimodal/media/video.py splits video/jpeg data URLs by comma to extract individual JPEG frames, but does not enforce a frame coun

[NVD] CVE-2026-34755 (MEDIUM 6.5) — vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.load_base64() method at vllm/multimodal/media/video.py splits video/jpeg data URLs by comma to extract individual JPEG frames, but does not enforce a frame coun

lownvdPublished 2026-04-06

CVE-2026-34755 CVSS: 6.5 MEDIUM Published: 2026-04-06T16:16:36.463

vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.load_base64() method at vllm/multimodal/media/video.py splits video/jpeg data URLs by comma to extract individual JPEG frames, but does not enforce a frame count limit. The num_frames parameter (default: 32), whi

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-34755