{"data":{"id":"b903fe08-b93d-4373-a11d-d37a5cb17e2b","title":"CVE-2026-73558: vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * ","summary":"vLLM is an inference and serving engine for large language models that had an integer overflow bug (a math error where a number gets too large for its storage space) in versions before 0.27.0. This bug could cause one user's AI inference result (the AI's output) to leak to another user processing a request in the same batch, exposing private data.","solution":"This issue is fixed in version 0.27.0.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73558","publishedAt":"2026-08-13T15:20:18.220Z","cveId":"CVE-2026-73558","cweIds":["CWE-190"],"cvssScore":"5.3","cvssSeverity":"medium","severity":"medium","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-13T15:20:18.220Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}