CVE Explorer
CVE-2026-22773
vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3 vision model implementation by sending a specially crafted 1x1 pixel image. This causes a tensor dimension mismatch that results in an unhandled runtime error, leading to complete server termination. This issue has been patched in version 0.12.0.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"vllm","vendor":"vllm-project","versions":[{"status":"affected","version":">= 0.6.4, < 0.12.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:cbf441eb46f4bfea177815723ab0d788d352b3c1ffb1246c78dffa62cb242e4a · sha256:daa5740a70bdcbd8… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:cbf441eb46f4bfea177815723ab0d788d352b3c1ffb1246c78dffa62cb242e4a · sha256:daa5740a70bdcbd8… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-770","description":"CWE-770: Allocation of Resources Without Limits or Throttling","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cbf441eb46f4bfea177815723ab0d788d352b3c1ffb1246c78dffa62cb242e4a · sha256:daa5740a70bdcbd8… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/vllm-project/vllm/security/advisories/GHSA-grg2-63fw-f2qr","tags":["x_refsource_CONFIRM"],"url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-grg2-63fw-f2qr"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cbf441eb46f4bfea177815723ab0d788d352b3c1ffb1246c78dffa62cb242e4a · sha256:daa5740a70bdcbd8… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.