{"data":{"id":"c88c3c60-3772-4363-adf0-ecb261768e41","title":"GHSA-85xf-c7hm-whqw: vLLM: Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service (3 sites)","summary":"vLLM versions 0.25.1 and earlier have a vulnerability where three different structured-output request paths (structured output is a feature that constrains an AI's responses to match a specific format) can trigger uncaught exceptions that crash the entire shared engine instead of failing just that one request, causing a denial of service (making the service unavailable) for all users on that engine. The root cause is missing error handling around grammar and token validation for structured output, allowing request-level errors to escape and kill the engine's core processing loop.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-85xf-c7hm-whqw","publishedAt":"2026-10-05T23:42:44.000Z","cveId":"CVE-2026-105757","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":["vllm@< 0.30.0 (fixed: 0.30.0)"],"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-10-05T23:42:44.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}