/Vulnerability Library

vLLM 0.8.3 - 0.14.0 - Information Disclosure

CVE-2026-22778
Verified

Description

vLLM 0.8.3 to - 0.14.1 contains an information disclosure caused by leaking a heap address in error messages from the multimodal endpoint when processing invalid images, letting remote attackers reduce ASLR entropy, exploit requires sending invalid images.

Severity

Critical

CVSS Score

9.8

Exploit Probability

11%

Affected Product

vllm

Published Date

June 21, 2026

Template Author

kenlacroix

CVE-2026-22778.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-22778
CWE ID:
cwe-209

References

https://github.com/vllm-project/vllm/security/advisories/GHSA-4r2x-xpjr-7cvvhttps://orca.security/resources/blog/cve-2026-22778-vllm-rce-vulnerability/https://nvd.nist.gov/vuln/detail/CVE-2026-22778

Remediation Steps

Upgrade to version 0.14.1 or later.