vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, and MediaConnector.fetch_video forwards that choice to VideoMed
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| vllm-project | vllm | < 0.28.0 |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vllm-project | vllm | < 0.28.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57173 | 6.5 MEDIUM | vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions |
| CVE-2026-92220 | 5.3 MEDIUM | vllm-project vLLM MoRIIO Acknowledgement moriio_connector.py MoRIIOWrapper._handle_release |
| CVE-2026-92365 | 4.3 MEDIUM | vllm-project vllm thinking_budget_state.py algorithmic complexity |
No comments yet