CVE-2026-9540

MEDIUM

vllm-project vllm OpenAI-compatible Serving Path denial of service

Title source: cna
STIX 2.1

Description

A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance.

References (7)

Core 7
Core References
Vdb Entry vdb-entry
VDB-365601 | vllm-project vllm OpenAI-compatible Serving Path denial of service
https://vuldb.com/vuln/365601
Signature, Permissions Required signature permissions-required
VDB-365601 | CTI Indicators (IOB, IOC, TTP)
https://vuldb.com/vuln/365601/cti
Third Party Advisory third-party-advisory
Submit #814645 | vllm-project vllm 0.19.0 Denial of Service
https://vuldb.com/submit/814645
Exploit exploit issue-tracking
https://github.com/vllm-project/vllm/issues/37343

Scores

CVSS v3 5.3
EPSS 0.0043
EPSS Percentile 33.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (1)
vllm-project/vllm 0.19.0
Published May 26, 2026
Tracked Since May 26, 2026