Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-98f3-hwg4-4rf7 | vllm has Improper Resource Shutdown or Release |
Tue, 26 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance. | |
| Title | vllm-project vllm OpenAI-compatible Serving Path denial of service | |
| First Time appeared |
Vllm-project
Vllm-project vllm |
|
| Weaknesses | CWE-404 | |
| CPEs | cpe:2.3:a:vllm-project:vllm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vllm-project
Vllm-project vllm |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-26T13:47:57.215Z
Reserved: 2026-05-26T05:44:55.913Z
Link: CVE-2026-9540
Updated: 2026-05-26T13:47:53.055Z
Status : Deferred
Published: 2026-05-26T14:16:45.803
Modified: 2026-06-17T11:05:27.720
Link: CVE-2026-9540
No data.
OpenCVE Enrichment
Updated: 2026-05-26T15:45:08Z
Github GHSA