Critical RCE in vLLM Allows Server Takeover via Malicious Video URL (CVE-2026-22778)

Introduction A critical vulnerability (CVE-2026-22778, CVSS 9.8) was disclosed on February 2, 2026, affecting vLLM, a widely-deployed Python library for serving large language models. The flaw allows unauthenticated attackers to achieve remote code execution by sending a specially crafted video URL to the API. No active exploitation has been publicly confirmed yet, but a detailed […]

The post Critical RCE in vLLM Allows Server Takeover via Malicious Video URL (CVE-2026-22778) appeared first on Orca Security.

原始链接: https://orca.security/resources/blog/cve-2026-22778-vllm-rce-vulnerability/
侵权请联系站方: [email protected]

相关推荐

换一批