DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-7v6w-cjch-9fr4

Package

lmcache-cuda-12.8

Component

vllm

Latest update

Pending upstream fix

Aliases

Severity

6.5

Medium

CVSS V3

Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://nvd.nist.gov/vuln/detail/CVE-2026-57173

Updates

Status

Pending upstream fix

Impact

CVE-2026-57173 (GHSA-hcwq-8wjf-3gcr) is an unauthenticated audio decompression-bomb denial of service in the vLLM chat completions endpoint, fixed upstream in vLLM 0.24.0 (https://github.com/vllm-project/vllm/pull/45908). This package pins vllm 0.19.1, the last release installable on a CUDA 12.8 stack: every vLLM release from 0.20.0 onward pins torch 2.11.0 (0.27.0+ torch 2.13.0), whose PyPI wheels require CUDA 13 bindings, so resolution against cuda-bindings~=12.8 is unsatisfiable. The vulnerable code (audio decoding without a duration limit in the chat path) is present in 0.19.1. Remediated in lmcache-cuda-13.0, which tracks current vLLM.

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.