CVE-2026-22778Disclosure(vllm / vllm)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vllm vllm systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guesses to ~8 guesses. This vulnerability can be chained a heap overflow with JPEG2000 decoder in OpenCV/FFmpeg to achieve remote code execution. This vulnerability is fixed in 0.14.1.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-532CWE-209

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vllm

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 22 mentions across 12 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 16 signals
  • Disclosure: 11 classified signals
  • General: 4 classified signals
  • Peaked 10d ago at 6 mentions (2026-02-03); latest day: 1
  • 22 total mentions across 12 days

Affected systems

Vendors
Products
vllm

Deep dive

Activity timeline22 mentions / 12d
02356Mentions · 2026-02-02: 3Mentions · 2026-02-03: 6Mentions · 2026-02-04: 1Mentions · 2026-02-05: 1Mentions · 2026-02-06: 2Mentions · 2026-02-08: 1Mentions · 2026-02-13: 1Mentions · 2026-03-11: 1Mentions · 2026-04-08: 1Mentions · 2026-06-05: 2Mentions · 2026-06-22: 2Mentions · 2026-06-28: 1PoC Mentioned / Linked · 2026-02-03: 2PoC Mentioned / Linked · 2026-02-13: 1PoC Mentioned / Linked · 2026-06-05: 1Patch / Workaround · 2026-02-02: 1Patch / Workaround · 2026-02-03: 3Patch / Workaround · 2026-02-04: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-02-02: 3Technical Details · 2026-02-03: 4Technical Details · 2026-02-04: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-06: 2Technical Details · 2026-02-08: 1Technical Details · 2026-02-13: 1Technical Details · 2026-03-11: 1Technical Details · 2026-04-08: 1Technical Details · 2026-06-28: 102-0202-0302-0402-0502-0602-0802-1303-1104-0806-0506-2206-28
Signal classification4 categories
Disclosure
1150.0%
Patch
627.3%
General
418.2%
PoC
14.5%
Referenced assets17 URLs
Classification over time
DateTotalLabels
2026-02-023
Disclosure2Patch1
2026-02-036
Disclosure2General1Patch3
2026-02-041
Patch1
2026-02-051
Disclosure1
2026-02-062
Disclosure2
2026-02-081
Disclosure1
2026-02-131
Disclosure1
2026-03-111
Disclosure1
2026-04-081
Patch1
2026-06-052
General1PoC1
2026-06-222
General2
2026-06-281
Disclosure1
Full discourse20 posts
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-22778 (CVSS N/A): vLLM Vulnerable to Remote Code Execution vLLM is vulnerable to unauthorized model access via improper authentication in the OpenAI-compatible API server, allowing unauthenticated attackers to list, load, or unload models and exfiltrate sensitive model weights. Search by vul.cve Filter 👉 vul.cve="CVE-2026-22778" ZoomEye Dork 👉 app="vLLM" 294 exposed instances. 🔥 CVE Feed Intelligence: https://www.darkeye.org/vuln/cve/CVE-2026-22778 ZoomEye Link: https://www.zoomeye.ai/searchResult?q=dnVsLmN2ZT0iQ1ZFLTIwMjYtMjI3Nzgi&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260206 Refer: https://nvd.nist.gov/vuln/detail/CVE-2026-22778 #ZoomEye #NetSec #OSINT #CyberSecurity #vLLM #AIsecurity #LLMsecurity #ZeroDay

    Post summary

    The tweet announces CVE-2026-22778, detailing RCE in vLLM due to improper authentication and noting 294 exposed instances, but provides no PoC, exploit, or patch information.

    04027122.9K
    11.9K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-22778 - critical 🚨 vLLM 0.8.3 - 0.14.0 - Information Disclosure > vLLM 0.8.3 to - 0.14.1 contains an information disclosure caused by leaking a heap ad... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-22778 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet alerts about a critical information‑disclosure vulnerability in selected vLLM versions, points to a library resource, but does not provide PoC or active exploitation details.

    00021372
    1.3K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-54236 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778, which introduced a sanitize_message helper t… https://www.cve.org/CVERecord?id=CVE-2026-54236

    Post summary

    The text merely notes the existence of CVE-2026-54236 related to vLLM, without any detailed vulnerability, exploit, or patch information.

    01011785
    57.7K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    A critical vulnerability CVE-2026-22778 in vLLM enables remote code execution via malicious video URLs on multimodal AI endpoints. Affected versions: >=0.8.3 & <0.14.1; patch vLLM 0.14.1 addresses this. #AIFlaw #RemoteExec #Python https://ift.tt/5nbXtSW

    Post summary

    A critical RCE flaw in vLLM has been disclosed with a patch released (0.14.1); no PoC or active exploitation is reported.

    01010106
    3.6K followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 Atenção, profissionais de #cibersegurança! A vulnerabilidade CVE-2026-22778 no vLLM permite execução remota de código via URL de vídeo maliciosa. Atualize para vLLM 0.14.1 IMEDIATAMENTE para proteger seus dados! 🔒 Saiba mais: https://orca.security/resources/blog/cve-2026-22778-vllm-rce-vulnerability/ #RCE #vLLM

    Post summary

    The post announces CVE-2026-22778, a remote code execution flaw in vLLM triggered by malicious video URLs, and urges users to immediately upgrade to vLLM 0.14.1 to mitigate the risk.

    0101094
    253 followersView on X
  • Eli Woodward@ElijahWoodward9
    General

    Full article https://www.ox.security/blog/cve-2026-22778-vllm-rce-vulnerability/

    Post summary

    The text merely references a blog article URL about CVE-2026-22778 without providing further details.

    0101084
    226 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-22778: CRITICAL] In vLLM versions 0.8.3 to 0.14.0, sending an invalid image resulted in a PIL error leak, exposing a heap address, making ASLR easier to bypass. Pairing this exploit with a heap ove...#cve,CVE-2026-22778,#cybersecurity https://cvefind.com/CVE-2026-22778

    Post summary

    The tweet discloses a critical CVE in vLLM that leaks heap addresses via a PIL error, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    01010114
    583 followersView on X
  • SRG@SimeonGarratt
    General

    @PsudoMike The satirical part is - their core infra/backend is already completely vulnerable and exposed. And it hasn't even started. (CVE-2026-22778), (CVE-2026-24779)... for starters.

    Post summary

    The tweet highlights the discovery of vulnerabilities (CVE-2026-22778, CVE-2026-24779) but offers no evidence of exploitation, remediation, or detailed technical info, making it a general disclosure.

    10000772
    1.3K followersView on X
  • Firmis Labs@FirmisLabs
    Patch

    CVE-2026-22778 · NIST 9.8/10 https://nvd.nist.gov/vuln/detail/CVE-2026-22778 ask your AI: "check if my project uses vllm and if it's below version 0.14.1" then: "update vllm to the latest version and make sure video processing still works"

    Post summary

    The message references CVE-2026-22778 with a high CVSS score and advises updating vllm to mitigate the vulnerability.

    1000032
    1 followersView on X
  • DotTechES@DotTechES
    Disclosure

    Ojo si usáis vLLM para inferencia local. Se confirma CVE-2026-22778 (9.8/10). Un simple vídeo malicioso te da RCE. Y OpenClaw llenándose de malware. La "Era de los Sistemas" va de asegurar la cadena de suministro, no de picar código rápido.

    Post summary

    The post confirms the high‑severity CVE‑2026‑22778, highlighting a malicious video that achieves RCE, but no active exploitation or patch information is provided.

    1000060
    1.0K followersView on X
  • Brandon Veiseh@BVeiseh
    Disclosure

    If you are running vLLM with video models, make sure to bump your versions. A pretty nasty security vulnerability was discovered yesterday. https://orca.security/resources/blog/cve-2026-22778-vllm-rce-vulnerability/?utm_source=linkedin&utm_medium=organic+social&utm_campaign=orca+blog

    Post summary

    A new CVE (CVE-2026-22778) affecting vLLM with video models has been discovered, prompting a recommendation to update versions.

    0001088
    378 followersView on X
  • Moshe Siman Tov Bustan@MosheTov
    Patch

    🚨 RCE ON vLLM! PATCH NOW! 🚨 A recently discovered vulnerability (CVE-2026-22778) in vLLM allows threat actors to send a malicious link to a vLLM service with the “video model” enabled in order to trigger an RCE, allowing complete takeover of the server! https://www.ox.security/blog/cve-2026-22778-vllm-rce-vulnerability/

    Post summary

    The text announces a remote code execution vulnerability in vLLM (CVE‑2026‑22778) and urges users to apply the available patch immediately.

    01000149
    78 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-54236 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778, which introduced a sanitize_message helper t… https://www.cve.org/CVERecord?id=CVE-2026-54236 ----- Traducción: CVE-2026-54236 vLL… http://infoflow.cloud`

    Post summary

    The text merely references CVE‑2026‑54236, providing a link to the CVE record without further details or actionable information.

    0000033
    88 followersView on X
  • SRG@SimeonGarratt
    PoC

    @RealNicoLagan Bumping this b/c 🙏 "Canada's 'big plan' is sitting with core infra/backend already completely vulnerable and exposed. If the govt is serious [PoC] (CVE-2026-22778), (CVE-2026-24779)... for starters."

    Post summary

    The tweet references CVE‑2026‑22778 and CVE‑2026‑24779, indicating that a proof‑of‑concept exists for these vulnerabilities affecting Canadian core infrastructure.

    0000066
    1.3K followersView on X
  • RagingCISO@CisoRaging77913
    Disclosure

    CVE-2026-22778: vLLM ASLR bypass → RCE. Invalid image triggers error that leaks heap addresses to client. Chain with existing overflow = silent RCE. Your cutting-edge LLM engine falls to an ancient PIL bug. AI stack maturity: pathetic.

    Post summary

    CVE-2026-22778 describes an ASLR bypass that leads to a silent remote code execution via an invalid image error leaking heap addresses and chaining with an existing overflow. No PoC, exploit code, patch, or evidence of active exploitation is mentioned.

    0000032
    5 followersView on X
  • The AI generalist@AIengineerlife
    Disclosure

    🚨 CVE-2026-22778 (CVSS 9.8): Critical RCE in vLLM AI library allows unauthenticated attackers to execute code via malicious video URLs. AI infrastructure under attack! Track 777+ CVEs with real-time alerts at https://threatmonitor.io #cybersecurity #CVE #infosec #vulnerability

    Post summary

    A critical RCE vulnerability (CVE‑2026‑22778) in the vLLM AI library is disclosed, allowing unauthenticated code execution via malicious video URLs; no patch or exploitation evidence is mentioned.

    0000057
    7 followersView on X
  • The AI generalist@AIengineerlife
    Disclosure

    🚨 CVE-2026-22778: Critical RCE in vLLM (CVSS 9.8) allows unauthenticated attackers to execute code via crafted video URLs. Track this & 777+ CVEs at https://threatmonitor.io Stay ahead of threats with real-time alerts! #cybersecurity #CVE #infosec #vulnerability

    Post summary

    The tweet announces CVE‑2026‑22778, a critical remote code execution flaw in vLLM that permits unauthenticated attackers to run code via crafted video URLs, but provides no evidence of exploitation, patches, or PoC.

    0000056
    7 followersView on X
  • Eyal Estrin ☁️@eyalestrin
    Disclosure

    Critical RCE in vLLM Allows Server Takeover via Malicious Video URL (CVE-2026-22778) http://dlvr.it/TQmWS0 #appsec

    Post summary

    A critical remote code execution flaw (CVE-2026-22778) in vLLM permits server takeover through a malicious video URL; the post offers no PoC, exploit code, or patch details.

    0000082
    2.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    vLLM has a Remote Code Execution vulnerability (CVE-2026-22778) in video processing. Update to 0.14.1 or later. #vLLM #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-22778-vllm-rce-video-processing

    Post summary

    vLLM CVE-2026-22778 is a remote code execution flaw in video processing; users are advised to update to v0.14.1 or newer to mitigate the risk.

    0000044
    1 followersView on X
  • Cyber Daily News@CyberDaily_News
    Patch

    vLLM 0.8.3-0.14.0 lets an attacker send a crafted video URL, leak a heap address and trigger a JPEG2000 overflow for full RCE (CVE-2026-22778). Patch to 0.14.1 or disable multimodal endpoints now. https://thecyberexpress.com/cve-2026-22778-vllm-rce-malicious-video-link/ #infosec #CVE2026-22778 #vLLM #RCE #AIsec

    Post summary

    vLLM 0.8.3-0.14.0 is vulnerable to full RCE via a JPEG2000 overflow triggered by crafted video URLs; patching to 0.14.1 or disabling multimodal endpoints is recommended, and a PoC link is provided.

    0000067
    12 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvllmvllm---

Explore more