THREAT OPS › Threat News › [GHSA] GHSA-8pw2-6jv3-mj5j (medium) — vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
[GHSA] GHSA-8pw2-6jv3-mj5j (medium) — vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
GHSA-8pw2-6jv3-mj5j Severity: medium CVE: CVE-2026-69147
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
## Summary
Current vLLM `main` lets an inference request choose the PyNvVideoCodec GPU video decoder through `media_io_kwargs.video.video_backend`, but engine GPU memory reservation is computed only from static startup configuration and `VLLM_VIDEO_LOADER_BA
Indicators of compromise
- ddd3855a28a561a5bb54d380c6e6b8b1e883cc4asha1
- af16446bf39de047ab57649c933063cf1cbf1e50sha1
- CVE-2026-69147cve
Original source: https://github.com/advisories/GHSA-8pw2-6jv3-mj5j