Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-92365

Опубликовано: 16 сент. 2026
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in vllm-project vllm. A remote attacker could exploit an algorithmic complexity vulnerability by manipulating unknown functionality within the thinking_budget_state.py file. This manipulation results in inefficient algorithmic complexity, which may lead to a Denial of Service (DoS), making the service unavailable to legitimate users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Affected
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Affected
Red Hat AI Inference Serverrhaii/vllm-cuda-rhel9Affected
Red Hat AI Inference Serverrhaii/vllm-gaudi-rhel9Affected
Red Hat AI Inference Serverrhaii/vllm-neuron-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2535464vllm: vllm-project vllm: Denial of Service via algorithmic complexity vulnerability

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
2 дня назад

A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.

CVSS3: 4.3
debian
2 дня назад

A vulnerability was found in vllm-project vllm up to 0.29.0. Affected ...

CVSS3: 4.3
github
2 дня назад

A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.

7.5 High

CVSS3