PatchSiren cyber security CVE debrief
CVE-2026-92365 vllm-project CVE debrief
A vulnerability was found in vllm-project vllm up to 0.29.0, affecting some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity, allowing remote attackers to launch an attack. The pull request to fix this issue awaits acceptance. Defenders should assess exposure and prioritize verification of the vulnerability's presence and potential impact on system performance, considering the inefficient algorithmic complexity.
- Vendor
- vllm-project
- Product
- vllm
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-09-22
Who should care
Defenders responsible for systems using vllm-project vllm up to 0.29.0 should assess exposure and prioritize verification of the vulnerability's presence and potential impact on system performance, considering the inefficient algorithmic complexity and potential for remote attacks. They should also review compensating controls, monitor for remote attacks, and plan for vendor-supported updates or mitigations where exposure is confirmed.
Why it matters
Defenders should prioritize verifying the presence of this vulnerability in their systems and assessing the potential impact of inefficient algorithmic complexity, as it allows remote attackers to manipulate the thinking_budget_state.py file.
- Verification of vulnerability presence in systems
- Assessment of potential impact on system performance
- Monitoring for remote attacks on affected functionality
Technical summary
The vulnerability affects vllm-project vllm up to 0.29.0, involving unknown functionality in the thinking_budget_state.py file. This allows remote manipulation that results in inefficient algorithmic complexity. Defenders should prioritize verifying the presence of this vulnerability in their systems and assessing the potential impact on system performance, considering the inefficient algorithmic complexity and potential for remote attacks. The vulnerability's technical details are limited, and further analysis is required to understand its full impact.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their systems and assessing the potential impact of inefficient algorithmic complexity.
Recommended defensive actions
- Verify the presence of vllm-project vllm up to 0.29.0 in your systems
- Assess the potential impact of inefficient algorithmic complexity
- Monitor for remote attacks on the affected functionality
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record and NVD entry provide information on the vulnerability, but details on affected versions, exploitation, and remediation are limited. Defenders should verify the presence of vllm-project vllm up to 0.29.0 in their systems, assess potential impact, and monitor for remote attacks on affected functionality. Evidence is limited, and further verification is required to confirm vulnerability presence and impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92365 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92365
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92365 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92365
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm/
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm/pull/51133
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-92365
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/935016
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/405451
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/405451/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.