{"id":"CVE-2026-55574","title":"vllm: vLLM: Denial of Service via adversarial regular expression in structured outputs API (CVE-2026-55574)","summary":"A flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for large language models (LLMs). A remote attacker could exploit this vulnerability by providing a specially crafted regular expression to the s…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-1333","vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","affected":["ai_inference_server","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","ai_inference_server 3.2","ai_inference_server 3.3","ai_inference_server 3.4"],"patched":["ai_inference_server 3.2","ai_inference_server 3.3","ai_inference_server 3.4"],"published":"2026-07-06","updated":"2026-09-21","sourceUpdated":"2026-09-21T16:31:59+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55574.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55574.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-55574"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2497509"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-55574"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55574"},{"url":"https://github.com/vllm-project/vllm/commit/2b3006076c5e9bc4cda9e03e3641388de3c5c286"},{"url":"https://github.com/vllm-project/vllm/pull/45118"},{"url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-rwxx-mrjm-wc2m"},{"url":"https://access.redhat.com/errata/RHSA-2026:61627"},{"url":"https://access.redhat.com/errata/RHSA-2026:61629"},{"url":"https://access.redhat.com/errata/RHSA-2026:60363"},{"url":"https://access.redhat.com/errata/RHSA-2026:69466"},{"url":"https://access.redhat.com/errata/RHSA-2026:69467"},{"url":"https://access.redhat.com/errata/RHSA-2026:69469"},{"url":"https://access.redhat.com/errata/RHSA-2026:69464"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2304.yaml"},{"url":"https://github.com/vllm-project/vllm"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.00583,"epssPercentile":0.46318,"aliases":["GHSA-rwxx-mrjm-wc2m","PYSEC-2026-2304"],"ecosystem":"pip","ingestedAt":"2026-07-13T18:58:08.974Z","slug":"CVE-2026-55574","body":"## Overview\n\nA flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for large language models (LLMs). A remote attacker could exploit this vulnerability by providing a specially crafted regular expression to the structured_outputs.regex API parameter. This adversarial regex, containing nested quantifiers, can cause an exponential expansion of the state-space in the grammar compiler, leading to an inference worker hanging indefinitely. This results in a Denial of Service (DoS) for the affected system.\n\n## Vendor advisories\n\n- **RHSA-2026:61627** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61627)\n- **RHSA-2026:61629** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61629)\n- **RHSA-2026:60363** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60363)\n- **RHSA-2026:69466** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69466)\n- **RHSA-2026:69467** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69467)\n- **RHSA-2026:69469** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69469)\n- **RHSA-2026:69464** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69464)\n- **Red Hat VEX** · Important · affected: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55574.json)\n\n**vllm: vLLM: Denial of Service via adversarial regular expression in structured outputs API** — rated Important by Red Hat. Released 2026-07-06, updated 2026-09-21.\n\nAffected:\n\n- Red Hat AI Inference Server\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n\nFixed:\n\n- Red Hat AI Inference Server 3.2\n- Red Hat AI Inference Server 3.3\n- Red Hat AI Inference Server 3.4\n\nNo fix planned:\n\n- Red Hat AI Inference Server\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n\nNot affected:\n\n- Red Hat OpenShift AI (RHOAI)\n\n## Remediation\n\nFor more information visit https://access.redhat.com/errata/RHSA-2026:61627 https://access.redhat.com/errata/RHSA-2026:61627\nFor more information visit https://access.redhat.com/errata/RHSA-2026:61629 https://access.redhat.com/errata/RHSA-2026:61629\nFor more information visit https://access.redhat.com/errata/RHSA-2026:60363 https://access.redhat.com/errata/RHSA-2026:60363\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-55574)\n\nAffected packages:\n\n- `vllm < 0.24.0`\n\nPatched in:\n\n- `vllm 0.24.0`\n\nSource: https://osv.dev/vulnerability/GHSA-rwxx-mrjm-wc2m","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}