CVE-2026-90878: vllm-project vLLM Jinja Template Rendering completions resource consumption
Published Sep 15, 2026
·Updated
A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chattemplate causes resource consumption. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
Affected Software
1 affected component
vllm-project vllm<=0.27.1
Event History
Sep 15, 2026
CVE Published
via MITRE·04:15 AM
Data Sourced
via MITRE·04:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to trigger the issue?
The attack requires low-level privileges. It does not require user interaction.
2
Is a vendor fix available?
A pull request to fix the issue is awaiting acceptance. The available information does not identify an accepted fix or a released fixed version.
3
How likely is exploitation?
The exploit has been publicly disclosed and may be used. The vulnerability’s exploit maturity is rated as proof-of-concept.