Описание
A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-90878
- https://github.com/vllm-project/vllm/issues/52025
- https://github.com/vllm-project/vllm/pull/52163
- https://github.com/vllm-project/vllm
- https://vuldb.com/cve/CVE-2026-90878
- https://vuldb.com/submit/927901
- https://vuldb.com/vuln/403472
- https://vuldb.com/vuln/403472/cti
Связанные уязвимости
A flaw was found in vllm-project vLLM. A remote attacker could exploit a vulnerability in the Jinja Template Rendering component by manipulating the `chat_template` argument. This manipulation leads to excessive resource consumption, potentially causing a Denial of Service (DoS) condition for the affected system.
A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
A vulnerability was determined in vllm-project vLLM up to 0.27.1. This ...