Security Advisory

CVE-2026-90878

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-15 04:15:11
Last updated 2026-09-15 13:54:06
Assigner VulDB
CVSS score 5.3
State PUBLISHED

Description

A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.