Beveiligingsadvies

CVE-2026-90878

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-15 04:15:11
Laatst bijgewerkt 2026-09-15 13:54:06
Toegewezen door VulDB
CVSS-score 5.3
Status PUBLISHED

Beschrijving

A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.