{"data":{"id":"57f9bd65-0045-4cf6-8bd0-64b311f4e930","title":"CVE-2026-103241: A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file…","summary":"A flaw in the Gemma4UnifiedParser component of vllm-project vLLM up to 0.26.0, located in rust/src/parser/src/unified/gemma4.rs, can be triggered remotely through a manipulated input to cause a denial of service. Public exploit code has been published, so the flaw can be used by attackers.","solution":"Upgrade to version 0.29.1rc0. The patch is commit 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103241","publishedAt":"2026-09-30T17:16:42.570Z","cveId":"CVE-2026-103241","cweIds":["CWE-404"],"cvssScore":"5.3","cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"vLLM denial of service through Gemma4UnifiedParser","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00714,"epssCheckedAt":"2026-10-10T06:41:57.681Z","kevDateAdded":null,"advisoryAliases":["GHSA-328r-mpfv-qc55"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:43:05.811Z","patchAvailable":null,"disclosureDate":"2026-09-30T17:16:42.570Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}