Логотип exploitDog
bind:CVE-2026-22778
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-22778

Количество 3

Количество 3

nvd логотип

CVE-2026-22778

7 дней назад

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guesses to ~8 guesses. This vulnerability can be chained a heap overflow with JPEG2000 decoder in OpenCV/FFmpeg to achieve remote code execution. This vulnerability is fixed in 0.14.1.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2026-22778

7 дней назад

vLLM is an inference and serving engine for large language models (LLM ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4r2x-xpjr-7cvv

7 дней назад

vLLM has RCE In Video Processing

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-22778

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guesses to ~8 guesses. This vulnerability can be chained a heap overflow with JPEG2000 decoder in OpenCV/FFmpeg to achieve remote code execution. This vulnerability is fixed in 0.14.1.

CVSS3: 9.8
0%
Низкий
7 дней назад
debian логотип
CVE-2026-22778

vLLM is an inference and serving engine for large language models (LLM ...

CVSS3: 9.8
0%
Низкий
7 дней назад
github логотип
GHSA-4r2x-xpjr-7cvv

vLLM has RCE In Video Processing

CVSS3: 9.8
0%
Низкий
7 дней назад

Уязвимостей на страницу