PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-92365 vllm-project CVE debrief

A vulnerability was found in vllm-project vllm up to 0.29.0, affecting some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity, allowing remote attackers to launch an attack. The pull request to fix this issue awaits acceptance. Defenders should assess exposure and prioritize verification of the vulnerability's presence and potential impact on system performance, considering the inefficient algorithmic complexity.

Vendor
vllm-project
Product
vllm
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-22
Advisory published
2026-09-16
Advisory updated
2026-09-22

Who should care

Defenders responsible for systems using vllm-project vllm up to 0.29.0 should assess exposure and prioritize verification of the vulnerability's presence and potential impact on system performance, considering the inefficient algorithmic complexity and potential for remote attacks. They should also review compensating controls, monitor for remote attacks, and plan for vendor-supported updates or mitigations where exposure is confirmed.

Why it matters

Defenders should prioritize verifying the presence of this vulnerability in their systems and assessing the potential impact of inefficient algorithmic complexity, as it allows remote attackers to manipulate the thinking_budget_state.py file.

  • Verification of vulnerability presence in systems
  • Assessment of potential impact on system performance
  • Monitoring for remote attacks on affected functionality

Technical summary

The vulnerability affects vllm-project vllm up to 0.29.0, involving unknown functionality in the thinking_budget_state.py file. This allows remote manipulation that results in inefficient algorithmic complexity. Defenders should prioritize verifying the presence of this vulnerability in their systems and assessing the potential impact on system performance, considering the inefficient algorithmic complexity and potential for remote attacks. The vulnerability's technical details are limited, and further analysis is required to understand its full impact.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their systems and assessing the potential impact of inefficient algorithmic complexity.

Recommended defensive actions

  • Verify the presence of vllm-project vllm up to 0.29.0 in your systems
  • Assess the potential impact of inefficient algorithmic complexity
  • Monitor for remote attacks on the affected functionality
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record and NVD entry provide information on the vulnerability, but details on affected versions, exploitation, and remediation are limited. Defenders should verify the presence of vllm-project vllm up to 0.29.0 in their systems, assess potential impact, and monitor for remote attacks on affected functionality. Evidence is limited, and further verification is required to confirm vulnerability presence and impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-92365 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-92365

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-92365 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92365

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.