vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3 vision model implementation by sending a specially crafted 1x1 pixel image. This causes a tensor dimension mismatch that results in an unhandled runtime error, leading to complete server termination. This issue has been patched in version 0.12.0.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-grg2-63fw-f2qr vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 12 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Vllm-project
Vllm-project vllm
Vendors & Products Vllm-project
Vllm-project vllm

Mon, 12 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 10 Jan 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Sat, 10 Jan 2026 06:45:00 +0000

Type Values Removed Values Added
Description vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3 vision model implementation by sending a specially crafted 1x1 pixel image. This causes a tensor dimension mismatch that results in an unhandled runtime error, leading to complete server termination. This issue has been patched in version 0.12.0.
Title vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-12T13:22:52.666Z

Reserved: 2026-01-09T18:27:19.387Z

Link: CVE-2026-22773

cve-icon Vulnrichment

Updated: 2026-01-12T13:22:49.721Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-10T07:16:03.527

Modified: 2026-01-13T14:03:18.990

Link: CVE-2026-22773

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-01-10T06:39:02Z

Links: CVE-2026-22773 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-01-12T14:36:26Z

Weaknesses