Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-90878

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A flaw was found in vllm-project vLLM. A remote attacker could exploit a vulnerability in the Jinja Template Rendering component by manipulating the chat_template argument. This manipulation leads to excessive resource consumption, potentially causing a Denial of Service (DoS) condition for the affected system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-gaudi-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-neuron-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2533580vllm: vLLM: Denial of Service via Jinja Template Rendering

EPSS

Процентиль: 23%
0.00303
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
2 дня назад

A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.

CVSS3: 4.3
debian
2 дня назад

A vulnerability was determined in vllm-project vLLM up to 0.27.1. This ...

CVSS3: 4.3
github
2 дня назад

A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.

EPSS

Процентиль: 23%
0.00303
Низкий

4.3 Medium

CVSS3