{"data":{"id":"e28ce988-5e07-4afc-975a-022ac61e888a","title":"CVE-2026-105775: A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function…","summary":"A security vulnerability in vllm-project vLLM up to 0.31.0 affects the function conv_ssm_forward in vllm/model_executor/layers/mamba/mamba_mixer2.py, within the Completions Request Handler component. Manipulation of this component leads to an out-of-bounds read, and the attack can be carried out remotely. The exploit has been publicly disclosed and may be used, and the project was informed through an issue report but has not yet responded.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105775","publishedAt":"2026-10-06T06:17:00.280Z","cveId":"CVE-2026-105775","cweIds":["CWE-119","CWE-125"],"cvssScore":"4.3","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00296,"epssCheckedAt":"2026-10-10T02:58:12.571Z","kevDateAdded":null,"advisoryAliases":["GHSA-qx62-jwpf-rcpj"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:42:49.448Z","patchAvailable":null,"disclosureDate":"2026-10-06T06:17:00.280Z","capecIds":["CAPEC-100","CAPEC-540"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}