CVE-2026-73556: CWE-400: Uncontrolled Resource Consumption in vllm-project vllm
CVE-2026-73556 is a denial-of-service vulnerability in the vllm project's lm-format-enforcer backend. The backend compiles attacker-supplied regular expressions without a timeout or buildability check, allowing a crafted regex to stall the engine worker by consuming excessive CPU. This issue affects versions of vllm prior to 0.26.0 when the lm-format-enforcer backend is explicitly enabled. The default backend is not affected. The vulnerability results in unauthenticated denial of service by hanging the structured-output compile step and blocking concurrent requests.
AI Analysis
Technical Summary
The vulnerability arises because the lm-format-enforcer backend in vllm compiles attacker-controlled regex patterns synchronously without applying a timeout or validating the regex's buildability. This contrasts with sibling backends (xgrammar and outlines) that use compile_regex_with_timeout to prevent catastrophic regex compilation. An attacker can submit a regex such as '(a{1,300}){300}' which causes the regex parser to consume 100% CPU core time indefinitely, resulting in a denial of service. The issue requires the operator to opt-in to the lm-format-enforcer backend via --structured-outputs-config. The vulnerability is tracked as CVE-2026-73556 with a CVSS 3.1 score of 5.3 (medium severity).
Potential Impact
An unauthenticated attacker can cause a denial of service by submitting a specially crafted regex to the lm-format-enforcer backend, which will hang the regex compilation step and stall the engine worker. This leads to CPU exhaustion and blocks processing of concurrent requests, effectively causing a service outage. The impact is limited to deployments that have explicitly enabled the vulnerable backend; the default backend is not affected.
Mitigation Recommendations
No official patch is currently confirmed. The suggested remediation is to apply the same compile_regex_with_timeout guard used in other backends to the lm-format-enforcer regex compilation and to add validation to reject un-buildable or oversized regex patterns. Operators should avoid enabling the lm-format-enforcer backend until a fix is released. Monitor the vendor advisory for updates on official fixes.
CVE-2026-73556: CWE-400: Uncontrolled Resource Consumption in vllm-project vllm
Description
CVE-2026-73556 is a denial-of-service vulnerability in the vllm project's lm-format-enforcer backend. The backend compiles attacker-supplied regular expressions without a timeout or buildability check, allowing a crafted regex to stall the engine worker by consuming excessive CPU. This issue affects versions of vllm prior to 0.26.0 when the lm-format-enforcer backend is explicitly enabled. The default backend is not affected. The vulnerability results in unauthenticated denial of service by hanging the structured-output compile step and blocking concurrent requests.
CVSS v3.1
Score 5.3medium
Affected software
vllm-project
vllm
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises because the lm-format-enforcer backend in vllm compiles attacker-controlled regex patterns synchronously without applying a timeout or validating the regex's buildability. This contrasts with sibling backends (xgrammar and outlines) that use compile_regex_with_timeout to prevent catastrophic regex compilation. An attacker can submit a regex such as '(a{1,300}){300}' which causes the regex parser to consume 100% CPU core time indefinitely, resulting in a denial of service. The issue requires the operator to opt-in to the lm-format-enforcer backend via --structured-outputs-config. The vulnerability is tracked as CVE-2026-73556 with a CVSS 3.1 score of 5.3 (medium severity).
Potential Impact
An unauthenticated attacker can cause a denial of service by submitting a specially crafted regex to the lm-format-enforcer backend, which will hang the regex compilation step and stall the engine worker. This leads to CPU exhaustion and blocks processing of concurrent requests, effectively causing a service outage. The impact is limited to deployments that have explicitly enabled the vulnerable backend; the default backend is not affected.
Mitigation Recommendations
No official patch is currently confirmed. The suggested remediation is to apply the same compile_regex_with_timeout guard used in other backends to the lm-format-enforcer regex compilation and to add validation to reject un-buildable or oversized regex patterns. Operators should avoid enabling the lm-format-enforcer backend until a fix is released. Monitor the vendor advisory for updates on official fixes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-12T20:53:46.380Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7ddecdbf8831d5395d0180
Added to database: 08/13/2026, 15:12:13 UTC
Last enriched: 09/13/2026, 13:04:02 UTC
Last updated: 09/28/2026, 17:22:18 UTC
Views: 65
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.