---
id: CVE-2026-90878
title: A vulnerability was determined in vllm-project vLLM up to 0.27.1
summary: >-
  A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects
  an unknown part of the file /v1/chat/completions of the component Jinja
  Template Rendering. This manipulation of the argument chat_template causes
  resource co…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-400
  - CWE-404
  - CWE-606
vendor: vllm-project
product: vLLM
affected:
  - vLLM 0.27.0
  - vLLM 0.27.1
published: '2026-09-15'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T14:37:14.523'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90878'
references:
  - url: 'https://github.com/vllm-project/vllm/'
    label: cna@vuldb.com
  - url: 'https://github.com/vllm-project/vllm/issues/52025'
    label: cna@vuldb.com
  - url: 'https://github.com/vllm-project/vllm/pull/52163'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90878'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/927901'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403472'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403472/cti'
    label: cna@vuldb.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90878.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-90878'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2533580'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-90878'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90878'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T13:41:58.979010Z'
epss: 0.00533
epssPercentile: 0.42499
ingestedAt: '2026-09-15T05:28:50.102Z'
---

## Overview

A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90878.json)
