在 vllm-project 的 vLLM 0.26.0/0.27.0 版本中发现了一个漏洞。受影响的文件是 中 MoRIIO 确认处理程序(MoRIIO Acknowledgement Handler)组件的 、 和 函数。通过操纵 或 参数,可能导致资源被大量消耗。攻击者可以远程发起此攻击。项目方已较早通过拉取请求(Pull Request)获知该问题,但尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vllm-project | vLLM | 0.26.0 |
cpe:2.3:a:vllm-project:vllm:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57173 | 6.5 MEDIUM | vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions |
| CVE-2026-92365 | 4.3 MEDIUM | vllm-project vllm thinking_budget_state.py algorithmic complexity |
No comments yet