PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2026-22778

9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guesses to ~8 guesses. This vulnerability can be chained a heap overflow with JPEG2000 decoder in OpenCV/FFmpeg to achieve remote code execution. This vulnerability is fixed in 0.14.1.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
vllmred hat ai inference server 3.2red hat ai inference server 3.3red hat openshift ai 2.25red hat openshift ai 3.3red hat ai inference server
Updated Sep 22, 2026View on NVD →
S4E scanner
criticalMisconfiguration~10 seconds

CVE-2026-22778 Scanner

CVE-2026-22778 Scanner - Information Disclosure vulnerability in vLLM

Used 3.4k times · 5.9k assets checked · domain, subdomain, ipv4

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →