Impact
A vulnerability was identified in vLLM prior to version 0.27.1 whereby manipulation of the ‘chat_template’ argument within the /v1/chat/completions endpoint can trigger excessive resource consumption during Jinja template rendering. The issue exploits uncontrolled resource usage (CWE‑400) and potential improper handling of unexpected conditions (CWE‑404). If exploited, the server may become unable to process legitimate requests, leading to denial of service and potential availability loss. The flaw is remote and does not require local privilege.
Affected Systems
The affected software is the vllm‑project vLLM library. All versions up to and including 0.27.1 component of vLLM; no specific platform constraints are listed.
Risk and Exploitability
Based on its CVSS score of 5.3, this vulnerability is classified as moderate severity. The EPSS score of < 1% indicates a very low exploitation probability, and it is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by submitting crafted chat_template payloads to the /v1/chat/completions endpoint, causing excessive resource consumption during Jinja template rendering. Public exploitation has been disclosed, and active misuse may result in CPU, memory, or other resource exhaustion, potentially leading to denial of service for legitimate users.
OpenCVE Enrichment