CVE-2026-92365

Severity CVSS v4.0:
MEDIUM
Type:
CWE-404 Improper Resource Shutdown or Release
Publication date:
16/09/2026
Last modified:
22/09/2026

Description

A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.