THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8737-qx52-hjff (medium) — vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

[GHSA] GHSA-8737-qx52-hjff (medium) — vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

highgithub_advisoriesPublished 2026-09-04

GHSA-8737-qx52-hjff Severity: medium CVE: CVE-2026-71486

vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

## Summary

The `/v1/completions/derender` and `/v1/chat/completions/derender` endpoints accept caller-supplied `GenerateResponse` objects and postprocess every nested `choices[*].token_ids` list directly. Unlike the normal render/generate path

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8737-qx52-hjff