CVE-2026-22778

CRITICAL NUCLEI

vLLM 0.8.3-0.14.0 - Information Disclosure via Multimodal Endpoint Error Handling

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2026-22778 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guesses to ~8 guesses. This vulnerability can be chained a heap overflow with JPEG2000 decoder in OpenCV/FFmpeg to achieve remote code execution. This vulnerability is fixed in 0.14.1.

Nuclei Templates (1)

vLLM 0.8.3 - 0.14.0 - Information Disclosure
CRITICALVERIFIEDby kenlacroix
Shodan: http.html:"/v1/models" http.html:"vllm"

Scores

CVSS v3 9.8
EPSS 0.0372
EPSS Percentile 88.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-209 CWE-532
Status published
Products (3)
pypi/vllm 0.8.3 - 0.14.1PyPI
vllm/vllm 0.8.3 - 0.14.1
vllm-project/vllm >= 0.8.3, < 0.14.1
Published Feb 02, 2026
Tracked Since Feb 18, 2026