CVE-2026-73556Disclosure(vllm / vllm)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vllm vllm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer.RegexParser without compile_regex_with_timeout or validation in validate_structured_output_request_lm_format_enforcer, allowing an unauthenticated /v1/completions request against the lm-format-enforcer backend to consume a CPU core and stall the structured-output engine path with a catastrophic regular expression. This issue is fixed in version 0.26.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-1333

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vllm

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-13); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
vllm

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-13: 2Mentions · 2026-08-14: 1Patch / Workaround · 2026-08-14: 1Technical Details · 2026-08-13: 1Technical Details · 2026-08-14: 108-1308-14
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-132
Disclosure1General1
2026-08-141
Patch1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-73556 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_for… https://www.cve.org/CVERecord?id=CVE-2026-73556

    Post summary

    The post references CVE-2026-73556 affecting vLLM before version 0.26.0 but lacks PoC, exploit details, active exploitation evidence, or specific remediation guidance.

    000201.2K
    58.1K followersView on X
  • Abdullah Kareem@CyberKareem
    Patch

    New CVE-2026-73556 in https://vllm.ai. An earlier fix added a regex-compile timeout to 2 of 3 structured-output backends. The 3rd (lm-format-enforcer) was missed, one catastrophic regex pegs a CPU core and stalls the engine. Unauthenticated DoS. #CVE #Research https://t.co/fZMONcjfJJ

    Post summary

    A DoS vulnerability (CVE‑2026‑73556) in vllm.ai is caused by a catastrophic regex in the lm‑format‑enforcer backend; a prior patch covered two backends but not the third, revealing a missing workaround.

    0000069
    243 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-73556 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_for… https://www.cve.org/CVERecord?id=CVE-2026-73556 ----- Traducción: CVE-2026-73556 vLL… https://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-73556 for vLLM, pointing to a specific parameter in older versions that is vulnerable, but it lacks exploitation details, patch information, or a PoC.

    0000027
    97 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvllmvllm---

Explore more