logo

Video of Death: Critical vLLM Flaw (CVSS 9.8) Grants Remote Code Execution

ID: e7e65149-ab98-577a-8770-3ca356020609

STIX ID: report--e7e65149-ab98-577a-8770-3ca356020609

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-02-05

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical RCE vulnerability (CVE-2026-22778, CVSS 9.8) in vLLM allows attackers to achieve arbitrary code execution by sending a malicious video file: an information leak in PIL reveals memory addresses to bypass ASLR, then a heap overflow in the JPEG2000 decoder (OpenCV/FFmpeg) enables hijacking execution. Default vLLM installs often lack authentication, increasing exposure for deployments serving video models; affected vLLM versions are >=0.8.3 and <0.14.1 and administrators are urged to upgrade to 0.14.1+ immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.