CVE-2026-92365: Inefficient Algorithmic Complexity in vllm-project vllm
A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.
AI Analysis
Technical Summary
This vulnerability in vllm-project vllm affects versions 0.1 through 0.29.0. It is caused by inefficient algorithmic complexity in an unspecified functionality within the file vllm/v1/sample/thinking_budget_state.py. The issue can be exploited remotely without user interaction or privileges, potentially leading to degraded performance or denial of service conditions. A pull request containing a fix exists but has not been merged or released yet.
Potential Impact
The vulnerability allows remote attackers to cause inefficient algorithmic complexity, which may degrade system performance or availability. There is no indication of privilege escalation, data confidentiality, or integrity impact. No known exploits are reported in the wild.
Mitigation Recommendations
No official fix is currently available as the pull request to address the issue is pending acceptance. Users should monitor the vendor's repository or advisories for the acceptance and release of the patch. Until then, consider limiting exposure of the vulnerable functionality to untrusted networks if possible.
CVE-2026-92365: Inefficient Algorithmic Complexity in vllm-project vllm
Description
A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.
CVSS v4.0
Score 5.3medium
Affected software
vllm-project
vllm
pkg:pypi/vllmcpe:2.3:a:vllm-project:vllm:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in vllm-project vllm affects versions 0.1 through 0.29.0. It is caused by inefficient algorithmic complexity in an unspecified functionality within the file vllm/v1/sample/thinking_budget_state.py. The issue can be exploited remotely without user interaction or privileges, potentially leading to degraded performance or denial of service conditions. A pull request containing a fix exists but has not been merged or released yet.
Potential Impact
The vulnerability allows remote attackers to cause inefficient algorithmic complexity, which may degrade system performance or availability. There is no indication of privilege escalation, data confidentiality, or integrity impact. No known exploits are reported in the wild.
Mitigation Recommendations
No official fix is currently available as the pull request to address the issue is pending acceptance. Users should monitor the vendor's repository or advisories for the acceptance and release of the patch. Until then, consider limiting exposure of the vulnerable functionality to untrusted networks if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-16T05:49:03.374Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aaaa16f55bf5e2cf5b35d4a
Added to database: 09/16/2026, 14:02:23 UTC
Last enriched: 09/16/2026, 14:31:48 UTC
Last updated: 09/17/2026, 02:27:19 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.