PT-2026-2260 · Vllm · Vllm

Oxcabe

·

Published

2026-01-10

·

Updated

2026-01-13

·

CVE-2026-22773

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions vLLM versions 0.6.4 through 0.11.9
Description vLLM is an inference and serving engine for large language models (LLMs). Users can cause the vLLM engine to crash when serving multimodal models that utilize the Idefics3 vision model implementation. This is achieved by submitting a specifically designed 1x1 pixel image. The crafted image triggers a tensor dimension mismatch, resulting in an unhandled runtime error and complete server termination.
Recommendations Update to version 0.12.0 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2026-22773
GHSA-GRG2-63FW-F2QR
PYSEC-2026-143

Affected Products

Vllm