---
id: CVE-2026-55574
title: >-
  vllm: vLLM: Denial of Service via adversarial regular expression in structured
  outputs API (CVE-2026-55574)
summary: >-
  A flaw was found in vLLM, a high-throughput and memory-efficient inference and
  serving engine for large language models (LLMs). A remote attacker could
  exploit this vulnerability by providing a specially crafted regular expression
  to the s…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-1333
vendor: Red Hat
product: Red Hat AI Inference Server 3.4
affected:
  - ai_inference_server
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - ai_inference_server 3.2
  - ai_inference_server 3.3
  - ai_inference_server 3.4
patched:
  - ai_inference_server 3.2
  - ai_inference_server 3.3
  - ai_inference_server 3.4
published: '2026-07-06'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T05:56:12+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55574.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55574.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-55574'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2497509'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-55574'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55574'
  - url: >-
      https://github.com/vllm-project/vllm/commit/2b3006076c5e9bc4cda9e03e3641388de3c5c286
  - url: 'https://github.com/vllm-project/vllm/pull/45118'
  - url: >-
      https://github.com/vllm-project/vllm/security/advisories/GHSA-rwxx-mrjm-wc2m
  - url: 'https://access.redhat.com/errata/RHSA-2026:61627'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61629'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60363'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69466'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70965'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70979'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69467'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70995'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69469'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70969'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69464'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2304.yaml
  - url: 'https://github.com/vllm-project/vllm'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00583
epssPercentile: 0.46611
aliases:
  - GHSA-rwxx-mrjm-wc2m
  - PYSEC-2026-2304
ecosystem: pip
ingestedAt: '2026-07-13T18:58:08.974Z'
---

## Overview

A flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for large language models (LLMs). A remote attacker could exploit this vulnerability by providing a specially crafted regular expression to the structured_outputs.regex API parameter. This adversarial regex, containing nested quantifiers, can cause an exponential expansion of the state-space in the grammar compiler, leading to an inference worker hanging indefinitely. This results in a Denial of Service (DoS) for the affected system.

## Vendor advisories

- **RHSA-2026:61627** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61627)
- **RHSA-2026:61629** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61629)
- **RHSA-2026:60363** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60363)
- **RHSA-2026:69466** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69466)
- **RHSA-2026:70965** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70965)
- **RHSA-2026:70979** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70979)
- **RHSA-2026:69467** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69467)
- **RHSA-2026:70995** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70995)
- **RHSA-2026:69469** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69469)
- **RHSA-2026:70969** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70969)
- **RHSA-2026:69464** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69464)
- **Red Hat VEX** · Important · affected: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55574.json)

**vllm: vLLM: Denial of Service via adversarial regular expression in structured outputs API** — rated Important by Red Hat. Released 2026-07-06, updated 2026-09-24.

Affected:

- Red Hat AI Inference Server
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)

Fixed:

- Red Hat AI Inference Server 3.2
- Red Hat AI Inference Server 3.3
- Red Hat AI Inference Server 3.4

No fix planned:

- Red Hat AI Inference Server
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)

Not affected:

- Red Hat OpenShift AI (RHOAI)

## Remediation

For more information visit https://access.redhat.com/errata/RHSA-2026:61627 https://access.redhat.com/errata/RHSA-2026:61627
For more information visit https://access.redhat.com/errata/RHSA-2026:61629 https://access.redhat.com/errata/RHSA-2026:61629
For more information visit https://access.redhat.com/errata/RHSA-2026:60363 https://access.redhat.com/errata/RHSA-2026:60363

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-55574)

Affected packages:

- `vllm < 0.24.0`

Patched in:

- `vllm 0.24.0`

Source: https://osv.dev/vulnerability/GHSA-rwxx-mrjm-wc2m
