GHSA-2h9j-24rv-h4c7LowCVSS 4.3
A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-90878
- https://github.com/vllm-project/vllm/issues/52025
- https://github.com/vllm-project/vllm/pull/52163
- https://github.com/vllm-project/vllm
- https://vuldb.com/cve/CVE-2026-90878
- https://vuldb.com/submit/927901
- https://vuldb.com/vuln/403472
- https://vuldb.com/vuln/403472/cti
- https://github.com/advisories/GHSA-2h9j-24rv-h4c7