CVE-2026-92365: Vllm-Project Vllm
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.
Affected products
- Vllm-Project Vllm: version 0.1 only; version 0.2 only; version 0.3 only; version 0.4 only; version 0.5 only; version 0.6 only; …
Published 2026-09-16. Last modified 2026-09-22.