CVE-2026-55574Disclosure(vllm / vllm)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vllm vllm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular expression string directly to the grammar compiler backends with no compilation timeout; in the xgrammar backend the string reaches the regex compiler with no guard, and in the outlines backend the validation step blocks structural issues such as lookarounds and backreferences but performs no complexity analysis, so a pattern with nested quantifiers passes all checks and causes exponential state-space expansion, allowing a single request containing an adversarial regex to hang an inference worker indefinitely and deny service. This issue is fixed in version 0.24.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1333

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vllm

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
vllm

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-10: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-10: 107-10
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - vLLM regex-driven inference worker hang (CVE-2026-55574) vLLM passes user-supplied regular expressions from the structured_outputs.regex API parameter into its grammar compiler backends without enforcing a compilation timeout or complexity checks. The root cause is improper input validation and algorithmic complexity (regex/automata blowup) triggered by nested quantifiers that cause exponential state-space expansion during compilation. An attacker can exploit this remotely by submitting a crafted regex via the API, requiring no special privileges beyond access to an endpoint that accepts structured output constraints. Successful exploitation can indefinitely hang an inference worker, leading to denial of service and potential cascading capacity loss across the serving fleet. 👉 Affected: vLLM < 0.24.0 | Upgrade to 0.24.0

    Post summary

    The tweet discloses CVE-2026-55574, a regex-driven denial‑of‑service flaw in vLLM that can hang inference workers, and recommends upgrading to vLLM 0.24.0 for remediation.

    0000092
    246 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvllmvllm---

Explore more