criticalPrivacy violation UnknownPublish anonymously
vLLM RCE via Malicious Video URL (CVE-2026-22778)
by Publish anonymously · 2 days agoviews 0en
PII protected
Personal information such as emails, phone numbers, IDs and access tokens are automatically masked before publication.
CVSS 9.8. Critical RCE on vLLM deployments (3M+ monthly downloads) by submitting a malicious video link to the API. Chained exploit: information disclosure via PIL error message leaking heap address + FFmpeg JPEG2000 decoder heap overflow via OpenCV video processing. Affects vLLM 0.8.3 through 0.14.0. Fixed in 0.14.1.