CVE-2026-22778

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guesses to ~8 guesses. This vulnerability can be chained a heap overflow with JPEG2000 decoder in OpenCV/FFmpeg to achieve remote code execution. This vulnerability is fixed in 0.14.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*

History

23 Feb 2026, 18:19

Type Values Removed Values Added
References () https://github.com/vllm-project/vllm/pull/31987 - () https://github.com/vllm-project/vllm/pull/31987 - Issue Tracking, Patch
References () https://github.com/vllm-project/vllm/pull/32319 - () https://github.com/vllm-project/vllm/pull/32319 - Issue Tracking, Patch
References () https://github.com/vllm-project/vllm/releases/tag/v0.14.1 - () https://github.com/vllm-project/vllm/releases/tag/v0.14.1 - Release Notes
References () https://github.com/vllm-project/vllm/security/advisories/GHSA-4r2x-xpjr-7cvv - () https://github.com/vllm-project/vllm/security/advisories/GHSA-4r2x-xpjr-7cvv - Vendor Advisory
First Time Vllm
Vllm vllm
CPE cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*
Summary
  • (es) vLLM es un motor de inferencia y servicio para modelos de lenguaje grandes (LLM). Desde la versión 0.8.3 hasta antes de la 0.14.1, cuando se envía una imagen inválida al endpoint multimodal de vLLM, PIL lanza un error. vLLM devuelve este error al cliente, filtrando una dirección de montículo. Con esta fuga, reducimos ASLR de 4 mil millones de intentos a ~8 intentos. Esta vulnerabilidad puede encadenarse a un desbordamiento de montículo con el decodificador JPEG2000 en OpenCV/FFmpeg para lograr ejecución remota de código. Esta vulnerabilidad está corregida en la versión 0.14.1.

02 Feb 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-02 23:16

Updated : 2026-02-23 18:19


NVD link : CVE-2026-22778

Mitre link : CVE-2026-22778

CVE.ORG link : CVE-2026-22778


JSON object : View

Products Affected

vllm

  • vllm
CWE
CWE-532

Insertion of Sensitive Information into Log File