THREAT OPS › Threat News › [GHSA] GHSA-hcwq-8wjf-3gcr (medium) — vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
[GHSA] GHSA-hcwq-8wjf-3gcr (medium) — vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
GHSA-hcwq-8wjf-3gcr Severity: medium CVE: CVE-2026-57173
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
### Summary The audio decode-duration guard (`max_duration_s`, env `VLLM_MAX_AUDIO_DECODE_DURATION_S`, default 600s) that protects against audio decompression-bomb DoS is wired into **only** the speech-to-text path (`/v1/audio/transcriptions`). The **chat** audio pa
Indicators of compromise
- CVE-2026-57173cve
- CVE-2026-5497cve
Original source: https://github.com/advisories/GHSA-hcwq-8wjf-3gcr