
🚨 HIGH - vLLM regex-driven inference worker hang (CVE-2026-55574) vLLM passes user-supplied regular expressions from the structured_outputs.regex API parameter into its grammar compiler backends without enforcing a compilation timeout or complexity checks. The root cause is improper input validation and algorithmic complexity (regex/automata blowup) triggered by nested quantifiers that cause exponential state-space expansion during compilation. An attacker can exploit this remotely by submitting a crafted regex via the API, requiring no special privileges beyond access to an endpoint that accepts structured output constraints. Successful exploitation can indefinitely hang an inference worker, leading to denial of service and potential cascading capacity loss across the serving fleet. 👉 Affected: vLLM < 0.24.0 | Upgrade to 0.24.0
Post summary
The tweet discloses CVE-2026-55574, a regex-driven denial‑of‑service flaw in vLLM that can hang inference workers, and recommends upgrading to vLLM 0.24.0 for remediation.
