{"data":{"id":"93384dc5-170c-4394-9a77-6a8c1c7e329e","title":"CVE-2026-90878: A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/comp","summary":"A vulnerability was found in vLLM (a library for running large language models) version 0.27.1 and earlier, where attackers can manipulate the chat_template parameter to cause excessive resource consumption through Jinja template rendering (a system for dynamically generating text). The vulnerability can be exploited remotely, and a fix has been proposed but not yet officially accepted.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90878","publishedAt":"2026-09-15T05:16:59.420Z","cveId":"CVE-2026-90878","cweIds":["CWE-400","CWE-404"],"cvssScore":"4.3","cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vllm-project vLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-15T05:16:59.420Z","capecIds":["CAPEC-125","CAPEC-130"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}