logo

Critical vLLM Flaw Exposes Millions of AI Servers to Remote Code Execution

ID: bf2fa071-d57e-50ad-a894-d441d0e999fc

STIX ID: report--bf2fa071-d57e-50ad-a894-d441d0e999fc

Feed Name: The Cyber Express

Threat Score
78/100

Date Published: 2026-02-03

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

A critical remote code execution vulnerability (CVE-2026-22778) was disclosed in the vLLM Python package affecting versions >= 0.8.3 and < 0.14.1; it allows unauthenticated attackers to achieve full server takeover by submitting crafted video URLs to multimodal endpoints. The exploit chain combines a PIL error message that leaks a heap address (reducing ASLR effectiveness) with an FFmpeg 5.1.x JPEG2000 decoder heap overflow in OpenCV, enabling overwrite of heap objects and redirection to libc functions. Organizations should immediately upgrade to vLLM 0.14.1 (which includes an updated OpenCV) or disable video/multimodal support until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.