Description
A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion leading to Denial of Service
Action: Monitor
AI Analysis

Impact

A vulnerability was identified in vLLM prior to version 0.27.1 whereby manipulation of the ‘chat_template’ argument within the /v1/chat/completions endpoint can trigger excessive resource consumption during Jinja template rendering. The issue exploits uncontrolled resource usage (CWE‑400) and potential improper handling of unexpected conditions (CWE‑404). If exploited, the server may become unable to process legitimate requests, leading to denial of service and potential availability loss. The flaw is remote and does not require local privilege.

Affected Systems

The affected software is the vllm‑project vLLM library. All versions up to and including 0.27.1 component of vLLM; no specific platform constraints are listed.

Risk and Exploitability

Based on its CVSS score of 5.3, this vulnerability is classified as moderate severity. The EPSS score of < 1% indicates a very low exploitation probability, and it is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by submitting crafted chat_template payloads to the /v1/chat/completions endpoint, causing excessive resource consumption during Jinja template rendering. Public exploitation has been disclosed, and active misuse may result in CPU, memory, or other resource exhaustion, potentially leading to denial of service for legitimate users.

Generated by OpenCVE AI on September 17, 2026 at 18:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch as soon as it is released; the upstream fix is pending acceptance.
  • If a patch is not yet available, enforce strict input validation and size limits on the chat_template parameter to mitigate uncontrolled resource consumption (CWE‑400) and unchecked inputs (CWE‑606).
  • Consider temporarily disabling the /v1/chat/completions endpoint or the Jinja template rendering feature until a patch is applied to limit resource usage (CWE‑400, CWE‑404).
  • Implement application‑level resource quotas or rate limiting for the endpoint to prevent server overload (CWE‑400).

Generated by OpenCVE AI on September 17, 2026 at 18:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-606
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
Title vllm-project vLLM Jinja Template Rendering completions resource consumption
First Time appeared Vllm-project
Vllm-project vllm
Weaknesses CWE-400
CWE-404
CPEs cpe:2.3:a:vllm-project:vllm:*:*:*:*:*:*:*:*
Vendors & Products Vllm-project
Vllm-project vllm
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Vllm-project Vllm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:54:06.533Z

Reserved: 2026-09-14T07:16:13.062Z

Link: CVE-2026-90878

cve-icon Vulnrichment

Updated: 2026-09-15T13:41:59.930Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T05:16:59.420

Modified: 2026-09-15T14:37:14.523

Link: CVE-2026-90878

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T04:15:11Z

Links: CVE-2026-90878 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-606

    Unchecked Input for Loop Condition