vLLM 0.8.3 - 0.14.0 - Information Disclosure
CVE-2026-22778
Verified
Description
vLLM 0.8.3 to - 0.14.1 contains an information disclosure caused by leaking a heap address in error messages from the multimodal endpoint when processing invalid images, letting remote attackers reduce ASLR entropy, exploit requires sending invalid images.
Severity
Critical
CVSS Score
9.8
Exploit Probability
11%
Affected Product
vllm
Published Date
June 21, 2026
Template Author
kenlacroix
CVE-2026-22778.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-22778
CWE ID:
cwe-209
Remediation Steps
Upgrade to version 0.14.1 or later.