CVE-2026-55574High· 7.5▾ TwilightA flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for large language models (LLMs). A remote attacker could exploit this vulnerability by providing a specially crafted regular expression to the s…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
0.3% → 0.6%
Last analysed / modified upstream
A flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for large language models (LLMs). A remote attacker could exploit this vulnerability by providing a specially crafted regular expression to the structured_outputs.regex API parameter. This adversarial regex, containing nested quantifiers, can cause an exponential expansion of the state-space in the grammar compiler, leading to an inference worker hanging indefinitely. This results in a Denial of Service (DoS) for the affected system.
vllm: vLLM: Denial of Service via adversarial regular expression in structured outputs API — rated Important by Red Hat. Released 2026-07-06, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
For more information visit https://access.redhat.com/errata/RHSA-2026:61627 https://access.redhat.com/errata/RHSA-2026:61627 For more information visit https://access.redhat.com/errata/RHSA-2026:61629 https://access.redhat.com/errata/RHSA-2026:61629 For more information visit https://access.redhat.com/errata/RHSA-2026:60363 https://access.redhat.com/errata/RHSA-2026:60363
Workarounds / mitigations:
Affected packages:
vllm < 0.24.0Patched in:
vllm 0.24.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54234High· 7.5vllm: vLLM: Denial of Service via malformed speculative decoding workload (CVE-2026-54234)
CVE-2026-73556Medium· 5.3vLLM is an inference and serving engine for large language models
CVE-2026-81725Medium· 5.9nltk: NLTK: Regular Expression Denial of Service via malformed TEI blocks (CVE-2026-81725)
CVE-2026-80205High· 7.5nltk: NLTK: Denial of Service via unvalidated regular expressions (CVE-2026-80205)
CVE-2026-67422High· 7.5pymdown-extensions is a collection of extensions for the Python Markdown library
CVE-2026-26209Medium· 5.5cbor2: cbor2: Denial of Service due to uncontrolled recursion via crafted CBOR payloads (CVE-2026-26209)