CVE-2026-9540

Published: Mag 26, 2026 Last Modified: Mag 26, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 5,3
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: low
MEDIUM 5,0
Access Vector: network
Access Complexity: low
Authentication: none
Confidentiality: none
Integrity: none
Availability: partial

Description

AI Translation Available

A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance.

404

Improper Resource Shutdown or Release

Draft
Common Consequences
Security Scopes Affected:
Availability Other Confidentiality
Potential Impacts:
Dos: Resource Consumption (Other) Varies By Context Read Application Data
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/vllm-project/vllm/
https://github.com/vllm-project/vllm/issues/37343
https://github.com/vllm-project/vllm/pull/37594
https://ingero.io/debugging-vllm-latency-minimax-ollama-mcp/
https://vuldb.com/submit/814645
https://vuldb.com/vuln/365601
https://vuldb.com/vuln/365601/cti