PT-2026-93785 · Vllm · Vllm

·

CVE-2026-92365

·

Published

2026-09-16

·

Updated

2026-09-23

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions vllm versions prior to 0.30.0
Description A remote attack can be launched against the vllm/v1/sample/thinking budget state.py file, leading to inefficient algorithmic complexity. This condition occurs when certain functionality within the file is manipulated, causing the system to consume resources inefficiently.
Recommendations Update to version 0.30.0.

Exploit

Fix

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92365
OPENSUSE-SU-2026:11867-1

Affected Products

Vllm