Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-606 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 15 Sep 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. | |
| Title | vllm-project vLLM Jinja Template Rendering completions resource consumption | |
| First Time appeared |
Vllm-project
Vllm-project vllm |
|
| Weaknesses | CWE-400 CWE-404 |
|
| CPEs | cpe:2.3:a:vllm-project:vllm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vllm-project
Vllm-project vllm |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-15T04:15:11.051Z
Reserved: 2026-09-14T07:16:13.062Z
Link: CVE-2026-90878
No data.
Status : Received
Published: 2026-09-15T05:16:59.420
Modified: 2026-09-15T05:16:59.420
Link: CVE-2026-90878
OpenCVE Enrichment
Updated: 2026-09-15T08:30:13Z