MediumVulnerabilityLLM-specific
CVE-2026-105775: A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-105775
- Published
- Record updated
Summary
A security vulnerability in vllm-project vLLM up to 0.31.0 affects the function conv_ssm_forward in vllm/model_executor/layers/mamba/mamba_mixer2.py, within the Completions Request Handler component. Manipulation of this component leads to an out-of-bounds read, and the attack can be carried out remotely. The exploit has been publicly disclosed and may be used, and the project was informed through an issue report but has not yet responded.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Topics
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database