{"data":{"id":"2ca81c7a-3993-4a1b-ac2e-0ce55dcfa4b7","title":"CVE-2026-73556: vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex paramet","summary":"vLLM (a system for running and serving large language models) has a vulnerability in versions before 0.26.0 where the structured_outputs.regex parameter accepts user input without validation, allowing attackers to submit specially crafted regular expressions (patterns for matching text) that consume excessive CPU resources and freeze the system. An unauthenticated attacker can exploit this through the /v1/completions endpoint without needing a password or credentials.","solution":"Update vLLM to version 0.26.0 or later, which includes validation and a timeout mechanism (compile_regex_with_timeout) to prevent catastrophic regular expressions from consuming system resources.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73556","publishedAt":"2026-08-13T15:20:17.927Z","cveId":"CVE-2026-73556","cweIds":["CWE-400","CWE-1333"],"cvssScore":"5.3","cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-13T15:20:17.927Z","capecIds":["CAPEC-125","CAPEC-130"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}