THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8pw2-6jv3-mj5j (medium) — vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation

[GHSA] GHSA-8pw2-6jv3-mj5j (medium) — vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation

highgithub_advisoriesPublished 2026-09-17

GHSA-8pw2-6jv3-mj5j Severity: medium CVE: CVE-2026-69147

vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation

## Summary

Current vLLM `main` lets an inference request choose the PyNvVideoCodec GPU video decoder through `media_io_kwargs.video.video_backend`, but engine GPU memory reservation is computed only from static startup configuration and `VLLM_VIDEO_LOADER_BA

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8pw2-6jv3-mj5j