CVE-2026-90713
A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the fi
CVSS
3.3
Bajo
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 14 sept 2026 · Última mod.: 14 sept 2026 · CWE-404
Sin historial EPSS suficiente todavía.
A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.
- gist.github.comhttps://gist.github.com/Yunzez/4b08ec3568a8cbfb120062e2558382b8
- github.comhttps://github.com/vllm-project/vllm/
- github.comhttps://github.com/vllm-project/vllm/issues/50954
- github.comhttps://github.com/vllm-project/vllm/pull/51135
- vuldb.comhttps://vuldb.com/cve/CVE-2026-90713
- vuldb.comhttps://vuldb.com/submit/918762
- vuldb.comhttps://vuldb.com/vuln/403267
- vuldb.comhttps://vuldb.com/vuln/403267/cti
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-908784.3 MED—
———A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.7hCVE-2026-908305.3 MED—
———A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet.13hCVE-2026-908295.3 MED—
———A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.13hCVE-2026-908285.3 MED—
———A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.14hCVE-2026-908164.3 MED—
———A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial of service. The attack is possible to be carried out remotely. Upgrading to version 8.1 and 9.0 is able to mitigate this issue. The patch is named 64fafd63f0b4. Upgrading the affected component is recommended.15hCVE-2026-908024.4 MED—
———A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.15h