Loading market data...
← Back to CVE feed

CVE-2026-90878

MEDIUM CVSS 4.3 View on NVD ↗

Description

A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Published: Sep 15, 2026 05:16 UTC Modified: Sep 15, 2026 14:37 UTC