CVE-2026-90878
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Sep 15, 2026
Vendor
unknown
Description
A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.